RHSA-2022:1402MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization 2.6.10 RPMs security and bug fix update

Published
April 19, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-33195 — golang: net: lookup functions may return invalid host names CVE-2021-33197 — golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty CVE-2021-33198 — golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents

🎯 Affected products8

  • CNV 2.6 for RHEL 7
  • CNV 2.6 for RHEL 8
  • kubevirt-0:2.6.10-230.el7.src as a component of CNV 2.6 for RHEL 7
  • kubevirt-0:2.6.10-230.el8.src as a component of CNV 2.6 for RHEL 8
  • kubevirt-virtctl-0:2.6.10-230.el7.x86_64 as a component of CNV 2.6 for RHEL 7
  • kubevirt-virtctl-0:2.6.10-230.el8.x86_64 as a component of CNV 2.6 for RHEL 8
  • kubevirt-virtctl-redistributable-0:2.6.10-230.el7.x86_64 as a component of CNV 2.6 for RHEL 7
  • kubevirt-virtctl-redistributable-0:2.6.10-230.el8.x86_64 as a component of CNV 2.6 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (7)