RHSA-2023:5103MediumCVSS 6.5
Red Hat Security Advisory: OpenShift Virtualization 4.11.6 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode
🎯 Affected products44
- CNV 4.11 for RHEL 8
- container-native-virtualization/bridge-marker@sha256:ac5930d50ce8ccd4238297c7029eae6ff977b6b221f519dcf89fe19dc9124428_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/checkup-framework@sha256:1caa3c022deaaa47c087cb1f2c1219be79116165986cacc4fa37b535266fcd9e_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/cluster-network-addons-operator@sha256:4b4ca9d02267fb571625f918d4c6ed395d92161259242cab865b35d019d7e913_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/cnv-containernetworking-plugins@sha256:eb6c9f5eb58b6de6bc4cd7d048a5987fecd054aab0cee59b9478f0111efdb5ad_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/cnv-must-gather-rhel8@sha256:cd9fe237da25f4cf7ab07b7825eb777c2003a6a441db5917a82a706c0561984d_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hco-bundle-registry@sha256:9380f4548497fb686d1a8e58b99e193642fbf3fb833ac7c057d22f65ca300757_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-csi-driver-rhel8@sha256:f6b32695d5416d73c640191a8c17e2e4b0312b44a5a423df059f5dfcd1cb1b14_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-csi-driver@sha256:f6b32695d5416d73c640191a8c17e2e4b0312b44a5a423df059f5dfcd1cb1b14_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:3a8e1a34c6fc8c61fe2867801441bbb99577bf23d270b80d9caf52fb9b301f8d_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hostpath-provisioner-rhel8@sha256:da6b5e2aafe2ca0c90a7748379e476fa027c34ffe0802a8d615390aa24b67c30_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hyperconverged-cluster-operator@sha256:217a2b7ce56c29c1597e34ecb53bafc75e25fbcaede066d34626b8370de9aa1f_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:a2404f404b881b29bc69d6c87192ad80534c6fa459dd9b659ba1fe7a49c8fa01_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubemacpool@sha256:76602186ecc38db46cef56beb9a8c2bd4460be56794af636dd5c31d4026ba87a_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-console-plugin@sha256:c46a2681478b2b03cddfe7e3cd8c184a018d061f6b30a11ec16c2d1a339adfea_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-ssp-operator@sha256:dfcda07e27e4c170d08a4f91c37e54fc6a3cefdc5dace0c174d2b3657771b902_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:56b01b735ac16ab3518858e14cde99a06ad7aeab00cf4b6f9fe1395bcbc4b075_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:8bd115404333e316023a9276c609e98ebb50772f92cffe1c4ea41653825c8c45_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:ca5741a9970f8945239638bfce8327214e390d35b9f37ca65b8b0a9f67299889_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:7de2998bfbaa885d59dd2797f4abcafd23ba73c4754046f4d36cc535a208499a_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:29dd6334a8d7f7e328414176b4b76a54fe71d142a563cbfe41e14c7086d7e907_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:797f91b01ab0d3c8634e2502bb38a59ccd4a196eb146f812336b679ea9394795_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:d674619099ea50b0010444c717f5b235caa55c743e7c3d165a8b7ea92d07b375_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:e0945fc41e565da48e12731584d15c7f2c3ba390864d9f0d4283e7020aea08dc_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:e33643822bb0403125e84b990c920bf83e329e2cc2158126bf351f5b8295310b_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/kubevirt-template-validator@sha256:bd57238bd8bab4b74ede39d4619c2363258b703b46e3d0ce2f1f2563a2bd4094_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/libguestfs-tools@sha256:13b9e418907aae2a24f2588956bae8936b7eea3174c7f6a8ab26fabdefe6789c_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/ovs-cni-marker@sha256:c98a610e7feb36b91480f630f485faed59de92ec2b83f009bb161724c5546b71_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/ovs-cni-plugin@sha256:62b3c55916531e3f15bc6b7c7e23d25ee951aa5bfc7cca39eb2230505342d8d4_amd64 as a component of CNV 4.11 for RHEL 8
- container-native-virtualization/virt-api@sha256:93cd133ce3b520e1365e7f3e855fa065009053da634b3175ea89b7b3852de221_amd64 as a component of CNV 4.11 for RHEL 8
- +14 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:5103
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2160673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218193
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5103.json