RHSA-2022:8598HighCVSS 8.6
Red Hat Security Advisory: Red Hat Virtualization Host security update [ovirt-4.5.3-1]
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-3515 — libksba: integer overflow may lead to remote code execution CVE-2022-38177 — bind: memory leak in ECDSA DNSSEC verification code CVE-2022-38178 — bind: memory leaks in EdDSA DNSSEC verification code CVE-2022-40674 — expat: a use-after-free in the doContent function in xmlparse.c CVE-2022-41974 — device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2022:8598
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2127936
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2128601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2128602
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2128986
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2130769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135610
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_8598.json