Security update for kubevirt
Announcement ID: | SUSE-SU-2021:2274-1 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves one vulnerability and contains three features can now be installed.
Description:
This update for kubevirt fixes the following issues:
General:
- Updated kubevirt to version 0.40.0
- Fixed an issue when calling
virsh-domcapabilities
- Fixed the the wrong registry path for containers.
Security fixes:
- CVE-2021-20286: A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Containers Module 15-SP2
zypper in -t patch SUSE-SLE-Module-Containers-15-SP2-2021-2274=1
-
Containers Module 15-SP3
zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2021-2274=1
Package List:
-
Containers Module 15-SP2 (x86_64)
- kubevirt-virtctl-0.40.0-5.11.2
- containerized-data-importer-manifests-1.30.0-5.3.2
- kubevirt-manifests-0.40.0-5.11.2
- kubevirt-virtctl-debuginfo-0.40.0-5.11.2
-
Containers Module 15-SP3 (x86_64)
- kubevirt-virtctl-0.40.0-5.11.2
- kubevirt-manifests-0.40.0-5.11.2
- kubevirt-virtctl-debuginfo-0.40.0-5.11.2