-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Virtualization 4.11.0 RPMs security and bug fix update Advisory ID: RHSA-2022:6527-02 Product: cnv Advisory URL: https://access.redhat.com/errata/RHSA-2022:6527 Issue date: 2022-09-14 CVE Names: CVE-2022-27191 ==================================================================== 1. Summary: Red Hat OpenShift Virtualization release 4.11.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: CNV 4.11 for RHEL 7 - x86_64 CNV 4.11 for RHEL 8 - x86_64 3. Description: OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization 4.11.0 RPMs. Security Fix(es): * golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2051902 - 4.11.0 rpms 2064702 - CVE-2022-27191 golang: crash in a golang.org/x/crypto/ssh server 6. Package List: CNV 4.11 for RHEL 7: Source: kubevirt-4.11.0-643.el7.src.rpm x86_64: kubevirt-virtctl-4.11.0-643.el7.x86_64.rpm kubevirt-virtctl-redistributable-4.11.0-643.el7.x86_64.rpm CNV 4.11 for RHEL 8: Source: kubevirt-4.11.0-643.el8.src.rpm x86_64: kubevirt-virtctl-4.11.0-643.el8.x86_64.rpm kubevirt-virtctl-redistributable-4.11.0-643.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-27191 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYyMkzNzjgjWX9erEAQgG4RAAk4MHNM7335XuHsojYC7QkxUaHTkdHiLN kziuszf4kXR14nWZVCAdisOrTPMpl9m99WGsVvYdmwGkbJLQws+eSNDjrz3n81x+ sy+XJxKNKAUBejsbgoCeYDCUSe9M2ItUSkw6CNty3yEAgdAonC8RXOdiMly/0RzE OQpoA2sLENF+Bp8UUx82tv84uNae25cc3mx40qTtrJ6EFRBjB3V4H00yi4SAGcan Hf+ebQnpw3dfwRgQ3aRjD80Q5EMKPZeEF5CxfnJcMCKmuVt1tPEyQ/Zxgs9/rqQV Gn2IKn6+yA1uC5h+968yb8TrVJtctThstWmkEds7TAKxIMZVszRXi7uaUjG/w0FZ QPAjzm/zSIkl3v2J2Vz3k1/FXPpAMoqUvm7yFBft9AonfJkz3l5+HUydpxL/K6iO PuTK1oJeblZ80lA7TnrnFl4h8P81VWRhmuF1Gjw2cr1W21c2g+7In7YduXzxem60 6RGuay+cjdWmorHIPQEGShE5s6XXMfgtqEUiudSNH0EpKOO7WN46egNUMdWNJOIi Lb9BsINQVJW9YzSICbFc0HyNHLWAkD5PIQhvRgC3amvczMUnhwD4Touteas7Caf4 UEbPwIa2iFFiQ9B83kYwQEUVpNDfuOBhYsig8FtO3lO16o4NlIEbvPXhnG41kxFA TxAIVSVrto0=nuEE -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce