- Issued:
- 2021-06-01
- Updated:
- 2021-06-01
RHSA-2021:2179 - Security Advisory
Synopsis
Moderate: RHV Manager security update (ovirt-engine) [ovirt-4.4.6]
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated ovirt-engine packages that fix several bugs , security flaws and add various enhancements are now available.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The ovirt-engine package provides the manager for virtualization environments.
This manager enables admins to define hosts and networks, as well as to add
storage, create VMs and manage user permissions.
A list of bugs fixed in this update is available in the Technical Notes
book:
https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes
Security Fix(es):
- nodejs-lodash: command injection via template (CVE-2021-23337)
- nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions (CVE-2020-28500)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- This release adds the queue attribute to the virtio-scsi driver in the virtual machine configuration. This improvement enables multi-queue performance with the virtio-scsi driver. (BZ#911394)
- With this release, source-load-balancing has been added as a new sub-option for xmit_hash_policy. It can be configured for bond modes balance-xor (2), 802.3ad (4) and balance-tlb (5), by specifying xmit_hash_policy=vlan+srcmac. (BZ#1683987)
- The default DataCenter/Cluster will be set to compatibility level 4.6 on new installations of Red Hat Virtualization 4.4.6.; (BZ#1950348)
- With this release, support has been added for copying disks between regular Storage Domains and Managed Block Storage Domains.
It is now possible to migrate disks between Managed Block Storage Domains and regular Storage Domains. (BZ#1906074)
- Previously, the engine-config value LiveSnapshotPerformFreezeInEngine was set by default to false and was supposed to be uses in cluster compatibility levels below 4.4. The value was set to general version.
With this release, each cluster level has it's own value, defaulting to false for 4.4 and above. This will reduce unnecessary overhead in removing time outs of the file system freeze command. (BZ#1932284)
- With this release, running virtual machines is supported for up to 16TB of RAM on x86_64 architectures. (BZ#1944723)
- This release adds the gathering of oVirt/RHV related certificates to allow easier debugging of issues for faster customer help and issue resolution.
Information from certificates is now included as part of the sosreport. Note that no corresponding private key information is gathered, due to security considerations. (BZ#1845877)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Virtualization Manager 4.4 x86_64
Fixes
- BZ - 1113630 - [RFE] indicate vNICs that are out-of-sync from their configuration on engine
- BZ - 1310330 - [RFE] Provide a way to remove stale LUNs from hypervisors
- BZ - 1589763 - [downstream clone] Error changing CD for a running VM when ISO image is on a block domain
- BZ - 1621421 - [RFE] indicate vNIC is out of sync on network QoS modification on engine
- BZ - 1717411 - improve engine logging when migration fail
- BZ - 1766414 - [downstream] [UI] hint after updating mtu on networks connected to running VMs
- BZ - 1775145 - Incorrect message from hot-plugging memory
- BZ - 1821199 - HP VM fails to migrate between identical hosts (the same cpu flags) not supporting TSC.
- BZ - 1845877 - [RFE] Collect information about RHV PKI
- BZ - 1875363 - engine-setup failing on FIPS enabled rhel8 machine
- BZ - 1906074 - [RFE] Support disks copy between regular and managed block storage domains
- BZ - 1910858 - vm_ovf_generations is not cleared while detaching the storage domain causing VM import with old stale configuration
- BZ - 1917718 - [RFE] Collect memory usage from guests without ovirt-guest-agent and memory ballooning
- BZ - 1919195 - Unable to create snapshot without saving memory of running VM from VM Portal.
- BZ - 1919984 - engine-setup failse to deploy the grafana service in an external DWH server
- BZ - 1924610 - VM Portal shows N/A as the VM IP address even if the guest agent is running and the IP is shown in the webadmin portal
- BZ - 1926018 - Failed to run VM after FIPS mode is enabled
- BZ - 1926823 - Integrating ELK with RHV-4.4 fails as RHVH is missing 'rsyslog-gnutls' package.
- BZ - 1928158 - Rename 'CA Certificate' link in welcome page to 'Engine CA certificate'
- BZ - 1928188 - Failed to parse 'writeOps' value 'XXXX' to integer: For input string: "XXXX"
- BZ - 1928937 - CVE-2021-23337 nodejs-lodash: command injection via template
- BZ - 1928954 - CVE-2020-28500 nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions
- BZ - 1929211 - Failed to parse 'writeOps' value 'XXXX' to integer: For input string: "XXXX"
- BZ - 1930522 - [RHV-4.4.5.5] Failed to deploy RHEL AV 8.4.0 host to RHV with error "missing groups or modules: virt:8.4"
- BZ - 1930565 - Host upgrade failed in imgbased but RHVM shows upgrade successful
- BZ - 1930895 - RHEL 8 virtual machine with qemu-guest-agent installed displays Guest OS Memory Free/Cached/Buffered: Not Configured
- BZ - 1932284 - Engine handled FS freeze is not fast enough for Windows systems
- BZ - 1935073 - Ansible ovirt_disk module can create disks with conflicting IDs that cannot be removed
- BZ - 1942083 - upgrade ovirt-cockpit-sso to 0.1.4-2
- BZ - 1943267 - Snapshot creation is failing for VM having vGPU.
- BZ - 1944723 - [RFE] Support virtual machines with 16TB memory
- BZ - 1948577 - [welcome page] remove "Infrastructure Migration" section (obsoleted)
- BZ - 1949543 - rhv-log-collector-analyzer fails to run MAC Pools rule
- BZ - 1949547 - rhv-log-collector-analyzer report contains 'b characters
- BZ - 1950348 - Set compatibility level 4.6 for Default DataCenter/Cluster during new installations of RHV 4.4.6
- BZ - 1950466 - Host installation failed
- BZ - 1954401 - HP VMs pinning is wiped after edit->ok and pinned to first physical CPUs.
Red Hat Virtualization Manager 4.4
SRPM | |
---|---|
engine-db-query-1.6.3-1.el8ev.src.rpm | SHA-256: dedd1815070be19d22b67890921ac0beeabd9cd606a744408699841936271845 |
ovirt-cockpit-sso-0.1.4-2.el8ev.src.rpm | SHA-256: 7c52eaba7ca990fae511f63d577bdfcab69a2803eb65d373271c214b59349dd2 |
ovirt-engine-4.4.6.6-0.10.el8ev.src.rpm | SHA-256: 3c17d07c033abf05a1cdf7c495d22cc3720c431cd9ab26135c64b0611f327ffe |
ovirt-engine-dwh-4.4.6.2-1.el8ev.src.rpm | SHA-256: 0e7f8144cb7a2ac3211ef006b252591ea6df9102bd4c04968659141df5c39a2d |
ovirt-engine-ui-extensions-1.2.6-1.el8ev.src.rpm | SHA-256: 3762085cbfe79d97837541fb2985f588ceb0ac5f506b424788a55a35e015deee |
ovirt-web-ui-1.6.9-1.el8ev.src.rpm | SHA-256: 7f85aca3e94a722abba6a9015426ce1ab57e028ef6b4acb116365648204674ad |
rhv-log-collector-analyzer-1.0.8-1.el8ev.src.rpm | SHA-256: e6359d26314a4bc2af6b13d75713f602f40b32fbbad0d10ef56298cc827fa53b |
rhvm-branding-rhv-4.4.8-1.el8ev.src.rpm | SHA-256: d8b5ca74720650da7522958015d75097410389f14631daec840d82324232abf7 |
x86_64 | |
engine-db-query-1.6.3-1.el8ev.noarch.rpm | SHA-256: 927bcda001cefae93871158401d6c2252cc83a571983b395973d388161909229 |
ovirt-cockpit-sso-0.1.4-2.el8ev.noarch.rpm | SHA-256: 7bea7ea5bdc55bd19a433cff415ddcc316fac25c3273c43c8baa3147378349ce |
ovirt-engine-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 77ee84bdb8a26dc4bc5081bcf9862fe6cf77c83bbc8266e541f751ebc3f49433 |
ovirt-engine-backend-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: cab34481de11d1050d453f462921b877d7dc9d07ae5714a1856342afcf047751 |
ovirt-engine-dbscripts-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 7e02cf7653ce17ce65f2eb2ae1b24e47af2addb62979032eaef4df31aae456f0 |
ovirt-engine-dwh-4.4.6.2-1.el8ev.noarch.rpm | SHA-256: 3f9153543dd7dc79d7aa82d1b38abf5cde575ab54f914f13370a0ba38b026a02 |
ovirt-engine-dwh-grafana-integration-setup-4.4.6.2-1.el8ev.noarch.rpm | SHA-256: 6c202abe0c126f26a651162c668f3ac71ee6dba2131ff2acf02f56ce54ea1ae4 |
ovirt-engine-dwh-setup-4.4.6.2-1.el8ev.noarch.rpm | SHA-256: 648ffc89420cd249fb58d4f2152dd9241cc09b5fe49485671c669913cef19dd3 |
ovirt-engine-health-check-bundler-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: c95a0aea4f3f5d08598b81282273a94a1fa83cb9d1310ee0580fcf4f20074d5b |
ovirt-engine-restapi-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: a04b1c6b7b3e8c1810a7b28112dcb6287341235150a04d9c4f493ef1667f3057 |
ovirt-engine-setup-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: a3b2e5faaa7cc8140b1e0819fffdb62fbe2540f6a5dbd54d3ff33bba44462195 |
ovirt-engine-setup-base-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 0b01cc4fe2384c479d9b501d1da67a0b51e079e03e1a3e531414736529a881b8 |
ovirt-engine-setup-plugin-cinderlib-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 7f44ec4234090870323da243f5efec0a81e6003fa90067355b123f1e43dabc17 |
ovirt-engine-setup-plugin-imageio-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: fb701a96c74ba6feab0b50502207fe4585c1d171da9c1f7afad137d7704e2750 |
ovirt-engine-setup-plugin-ovirt-engine-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: c569d161277859a6a6026e4d9fcbb242ea4e2dc30d13a943365fcd259b8348cb |
ovirt-engine-setup-plugin-ovirt-engine-common-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 79efe347bcb7543312e0be37a27c1786aab3a0e852ba3eb224c19450469375c7 |
ovirt-engine-setup-plugin-vmconsole-proxy-helper-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 03591c3578a5b18a6205417300d10f76900adda537eb954b4b154bf2a5869ac9 |
ovirt-engine-setup-plugin-websocket-proxy-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 5cd4e4e5c59cd5ad14045d3b1c3e254839b8082069fcfc7d90eaa3bee3a817c4 |
ovirt-engine-tools-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 918ef63c6813f915eed6c0684c9eb1b2b0a8ea0b46b20aefbbb68b804ad84b66 |
ovirt-engine-tools-backup-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 49a87fd8ffa71c771210a3a3ccffb5d8a42658a8dca2fac4bfdd2a94773b7744 |
ovirt-engine-ui-extensions-1.2.6-1.el8ev.noarch.rpm | SHA-256: dc89eb90e6aa1c7a1640b30313a1145bb7a34b74462fa58bf79b307f7b61775a |
ovirt-engine-vmconsole-proxy-helper-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 742e6a47a42c08516e86171c61d8664eb47ff9b55a6956b81669434237c02dfd |
ovirt-engine-webadmin-portal-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: df6dbd0d72cb7bc3724ecc69a91a8800ad5fc74b2454d40e8d72c1a6e93a129a |
ovirt-engine-websocket-proxy-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 60adb22594fd1e089ed6bfcd6ecd68f93a83eb3b55465df5133933d7d66e8098 |
ovirt-web-ui-1.6.9-1.el8ev.noarch.rpm | SHA-256: b3d724c9739bcd661b79c2c969226d2625f829888c4dd9da6172db13a8ccb578 |
python3-ovirt-engine-lib-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: a1e7c675fa2e6148c9727000be36ab9be06e601ddf4818c558c136291f911e0f |
rhv-log-collector-analyzer-1.0.8-1.el8ev.noarch.rpm | SHA-256: 60c80e51efe2a5e481e30430043656376f981f1fc7bc1d953095165774f2a60a |
rhvm-4.4.6.6-0.10.el8ev.noarch.rpm | SHA-256: 87295fb0a0106a29cefb9a8323e3b7558f8b9ad9391934d33747c9c77fdcd094 |
rhvm-branding-rhv-4.4.8-1.el8ev.noarch.rpm | SHA-256: fb26c2ccf4bb93047087a2ccee972c59d1a3972fd3d7a4fc203d3e82abffde90 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.