RHSA-2021:3477HighCVSS 8.1
Red Hat Security Advisory: RHV-H security update (redhat-virtualization-host) 4.3.18
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-3621 — sssd: shell command injection in sssctl CVE-2021-3715 — kernel: use-after-free in route4_change() in net/sched/cls_route.c CVE-2021-22555 — kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c CVE-2021-31535 — libX11: missing request length checks CVE-2021-32399 — kernel: race condition for removal of the HCI controller
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2021:3477
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1961822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970807
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1975142
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1993988
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3477.json