RHSA-2021:3235HighCVSS 8.1
Red Hat Security Advisory: Red Hat Virtualization Host security and bug fix update [ovirt-4.4.7]
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-3609 — kernel: race condition in net/can/bcm.c leads to local privilege escalation CVE-2021-3621 — sssd: shell command injection in sssctl CVE-2021-22543 — kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks CVE-2021-22555 — kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c CVE-2021-38575 — edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2021:3235
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956284
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1975142
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1975177
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989397
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3235.json