-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Virtualization Host 4.4.z SP 1 security update
Advisory ID:       RHSA-2023:5209-01
Product:           Red Hat Virtualization
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:5209
Issue date:        2023-09-19
CVE Names:         CVE-2022-21216 CVE-2022-33196 CVE-2023-0286 
=====================================================================

1. Summary:

An update for redhat-release-virtualization-host and
redhat-virtualization-host is now available for Red Hat Virtualization 4
for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64
Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64

3. Description:

The redhat-virtualization-host packages provide the Red Hat Virtualization
Host. These packages include redhat-release-virtualization-host,
ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are
installed using a special build of Red Hat Enterprise Linux with only the
packages required to host virtual machines. RHVH features a Cockpit user
interface for monitoring the host's resources and performing administrative
tasks.

Security Fix(es):

* kernel: Intel firmware update for insufficient granularity of access
control in out-of-band management in some Intel Atom and Intel Xeon
Scalable Processors (CVE-2022-21216)

* kernel: Intel firmware update for Incorrect default permissions in some
memory controller configurations (CVE-2022-33196)

* openssl: X.400 address type confusion in X.509 GeneralName
(CVE-2023-0286)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/2974891

5. Bugs fixed (https://bugzilla.redhat.com/):

2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName
2171227 - CVE-2022-21216 kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors
2171252 - CVE-2022-33196 kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations

6. Package List:

Red Hat Virtualization 4 Hypervisor for RHEL 8:

Source:
redhat-virtualization-host-4.5.3-202309130206_8.6.src.rpm

x86_64:
redhat-virtualization-host-image-update-4.5.3-202309130206_8.6.x86_64.rpm

RHEL 8-based RHEV-H for RHEV 4 (build requirements):

Source:
redhat-release-virtualization-host-4.5.3-9.el8ev.src.rpm

noarch:
redhat-virtualization-host-image-update-placeholder-4.5.3-9.el8ev.noarch.rpm

x86_64:
redhat-release-virtualization-host-4.5.3-9.el8ev.x86_64.rpm
redhat-release-virtualization-host-content-4.5.3-9.el8ev.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-21216
https://access.redhat.com/security/cve/CVE-2022-33196
https://access.redhat.com/security/cve/CVE-2023-0286
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJlCRT6AAoJENzjgjWX9erEn3kP/jpQLhYEjcjoVjj4aVVSqtUW
Tp3szjYt0EgooPRM8xOA//ppONljLuqsDQG6XLxEHMDpjXoHsln83XGp3D5ykmpv
mDn3poUpTeu2gW93JQZE2Zcv5jUMmQHFS3m8jL6hiAGNnxBY2E2AMNUjFIWH0Tcg
xrREeMw3xWl7J9DY70hC8vZKR1bMKTIy8EsstkyyboZZylz0vOsGxTPHl/Ahg1D4
g3zGM5waqAn8wTf51KL3I5hsa8rIDjOaWJKnXQeiv9kn0ys/dRzc/obk2uol8hFP
r4YPgLsmYemvDoiR5oUXPibruKvVF5/6fpkp9k6uV811pM3RNgVdGLr5gkzAIXQ/
bK2QhisAUY9tYhQFgUKVZm4NSDHN+wX+fEOGa27EHJ8qRypXQI2zIOrFrJJ6KmqQ
CAkGqHAwJvzOaotVfwzq7l/t5NlJ7Uvg6V5WCjVdcM2v8+QX+cfEclUXnW/MkIL8
N/JWl2C1CfsPEtXJwz0/j0hyfdCceR61Wev1KT44n+zCX4O6F/TVIFW2niKuo9v5
fx8djQQRvuzyR94BtlOt6+DgQP72ap5fNJ8gQdDB8P9NllZNiLP9bqhpWztX7Lzg
iycHkypCutgV+6cVbet+qpkYLlCGmeVi2hRRGz+8pKILxBYTi9bBIkhAwGH9/Vzh
OqKKmBCKjuK/nk9SlhXl
=ujpL
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-5209:01 Important: Red Hat Virtualization Host 4.4.z SP 1

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

Summary

The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks.
Security Fix(es):
* kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors (CVE-2022-21216)
* kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations (CVE-2022-33196)
* openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/2974891

References

https://access.redhat.com/security/cve/CVE-2022-21216 https://access.redhat.com/security/cve/CVE-2022-33196 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Virtualization 4 Hypervisor for RHEL 8:
Source: redhat-virtualization-host-4.5.3-202309130206_8.6.src.rpm
x86_64: redhat-virtualization-host-image-update-4.5.3-202309130206_8.6.x86_64.rpm
RHEL 8-based RHEV-H for RHEV 4 (build requirements):
Source: redhat-release-virtualization-host-4.5.3-9.el8ev.src.rpm
noarch: redhat-virtualization-host-image-update-placeholder-4.5.3-9.el8ev.noarch.rpm
x86_64: redhat-release-virtualization-host-4.5.3-9.el8ev.x86_64.rpm redhat-release-virtualization-host-content-4.5.3-9.el8ev.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2023:5209-01
Product: Red Hat Virtualization
Advisory URL: https://access.redhat.com/errata/RHSA-2023:5209
Issued Date: : 2023-09-19
CVE Names: CVE-2022-21216 CVE-2022-33196 CVE-2023-0286

Topic

An update for redhat-release-virtualization-host andredhat-virtualization-host is now available for Red Hat Virtualization 4for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

RHEL 8-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64

Red Hat Virtualization 4 Hypervisor for RHEL 8 - x86_64


Bugs Fixed

2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName

2171227 - CVE-2022-21216 kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors

2171252 - CVE-2022-33196 kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations


Related News