-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: guestfs-tools security, bug fix, and enhancement update Advisory ID: RHSA-2022:7959-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7959 Issue date: 2022-11-15 CVE Names: CVE-2022-2211 ==================================================================== 1. Summary: An update for guestfs-tools is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, s390x, x86_64 3. Description: guestfs-tools is a set of tools that can be used to make batch configuration changes to guests, get disk used/free statistics, perform backups and guest clones, change registry/UUID/hostname info, build guests from scratch, and much more. Security Fix(es): * libguestfs: Buffer overflow in get_keys leads to DoS (CVE-2022-2211) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2059286 - RFE: Rebase guestfs-tools to 1.48 in RHEL 9.1 2072493 - [RFE] Request to add lvm system.devices cleanup operation to virt-sysprep 2075718 - Having to use "--selinux-relabel" is not intuitive given Red Hat products default to selinux enabled. 2089748 - Removal of "--selinux-relabel" option breaks existing scripts 2100862 - CVE-2022-2211 libguestfs: Buffer overflow in get_keys leads to DoS 2106286 - virt-sysprep: make an effort to support LUKS on LV 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: guestfs-tools-1.48.2-5.el9.src.rpm aarch64: guestfs-tools-1.48.2-5.el9.aarch64.rpm guestfs-tools-debuginfo-1.48.2-5.el9.aarch64.rpm guestfs-tools-debugsource-1.48.2-5.el9.aarch64.rpm noarch: virt-win-reg-1.48.2-5.el9.noarch.rpm s390x: guestfs-tools-1.48.2-5.el9.s390x.rpm guestfs-tools-debuginfo-1.48.2-5.el9.s390x.rpm guestfs-tools-debugsource-1.48.2-5.el9.s390x.rpm x86_64: guestfs-tools-1.48.2-5.el9.x86_64.rpm guestfs-tools-debuginfo-1.48.2-5.el9.x86_64.rpm guestfs-tools-debugsource-1.48.2-5.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-2211 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMidzjgjWX9erEAQh1Bg/+K+5p4OKmDWKd99Hn29Ow87+XRfhVNv/F jOb8SAOy0KnxyJgMPCEAD+JqARNMkAI14bcYYEAnLvOUJgkxEzaJiiwPLjsIgolK juf7fi8Ikl8VSRtoZIujpOGFqAEYeRxDUPt/p36mw/iLlRPZt9OvDSTl0kEo1FaZ v8BmbqLPr6wGiLZtQmJ0jO+2E1K2m1dmFcUeCt9crA0ehN3gpOULWorJyYtGnFKr dWtez1O6uurEl93IWbMM/n8C1vr1NYXqZo0GhfKXiSKiUmtR6a8WbzEr87nkK30E yoHPvhi1NgSZ8X1ONZ7MDBC+six+54VVqUyK/VMyLZE8/BozKEIOaCk8CBM4adJH 6KBW7y/nn40izHcYUcw44r/6B/09zeN5coYoIBqq+PUwwp5vTU8I17A8pZncxYPM e22eeTpID97lwT4AMeTXbC2EdMTMTNVsW13ZSONF3fXYMjGgcdoefeP803OUGIzm uus7znkLd5lR9V5KQnB60JBFVf6tEYqahQEI5E/UCDNJcw0UNTIegJUEXVBqBVqM wV63DANh2yvRWQsESMvxthWjxMVGkV+2R1P/2py5kD7mIUxlDLWJe3QKtJESTRkl TyIdgMQ9TIR2jSMz/cZ2gPdZgUOrNu6kvgZqoom3t1DcK+E465r9QA1jh/WoQfwl WbKw9UbaLms=j1SI -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce