RHSA-2022:1053HighCVSS 9.8
Red Hat Security Advisory: Red Hat Virtualization Host security and enhancement update [ovirt-4.4.10] Async #2
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-25235 — expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution CVE-2022-25236 — expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution CVE-2022-25315 — expat: Integer overflow in storeRawNames()
🎯 Affected products17
- RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-0:0.185-1.el8.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-debuginfo-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-debuginfod-client-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-debuginfod-client-debuginfo-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-debuginfod-debuginfo-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-debugsource-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-devel-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-libelf-debuginfo-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- elfutils-libs-debuginfo-0:0.185-1.el8.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-release-virtualization-host-0:4.4.10-3.el8ev.src as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- redhat-release-virtualization-host-0:4.4.10-3.el8ev.x86_64 as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- redhat-release-virtualization-host-content-0:4.4.10-3.el8ev.x86_64 as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
- redhat-virtualization-host-0:4.4.10-202203211649_8.5.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-virtualization-host-image-update-0:4.4.10-202203211649_8.5.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- redhat-virtualization-host-image-update-placeholder-0:4.4.10-3.el8ev.noarch as a component of RHEL 8-based RHEV-H for RHEV 4 (build requirements)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content. Please update the affected packages as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2022:1053
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034626
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048407
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056363
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2057048
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1053.json