Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:5103 - Security Advisory
Issued:
2023-09-12
Updated:
2023-09-12

RHSA-2023:5103 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Virtualization 4.11.6 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Virtualization release 4.11.6 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.11.6 images.

Security Fix(es):

  • openshift: OCP & FIPS mode (CVE-2023-3089)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Requested TSC frequency outside tolerance range & TSC scaling not supported (BZ#2151169)
  • User cannot get resource "virtualmachineinstances/portforward" in API group "subresources.kubevirt.io" (BZ#2160673)
  • 4.11.4 containers (BZ#2173835)
  • VMI with x86_Icelake fail when mpx feature is missing (BZ#2218193)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.11 for RHEL 8 x86_64
  • Red Hat Container Native Virtualization 4.11 for RHEL 7 x86_64

Fixes

  • BZ - 2151169 - Requested TSC frequency outside tolerance range & TSC scaling not supported
  • BZ - 2160673 - User cannot get resource "virtualmachineinstances/portforward" in API group "subresources.kubevirt.io"
  • BZ - 2173835 - 4.11.4 containers
  • BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
  • BZ - 2218193 - VMI with x86_Icelake fail when mpx feature is missing

CVEs

  • CVE-2016-3709
  • CVE-2022-4304
  • CVE-2022-4450
  • CVE-2023-0215
  • CVE-2023-0286
  • CVE-2023-0361
  • CVE-2023-2828
  • CVE-2023-3089
  • CVE-2023-3899
  • CVE-2023-38408

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

x86_64

container-native-virtualization/bridge-marker@sha256:ac5930d50ce8ccd4238297c7029eae6ff977b6b221f519dcf89fe19dc9124428
container-native-virtualization/checkup-framework@sha256:1caa3c022deaaa47c087cb1f2c1219be79116165986cacc4fa37b535266fcd9e
container-native-virtualization/cluster-network-addons-operator@sha256:4b4ca9d02267fb571625f918d4c6ed395d92161259242cab865b35d019d7e913
container-native-virtualization/cnv-containernetworking-plugins@sha256:eb6c9f5eb58b6de6bc4cd7d048a5987fecd054aab0cee59b9478f0111efdb5ad
container-native-virtualization/cnv-must-gather-rhel8@sha256:cd9fe237da25f4cf7ab07b7825eb777c2003a6a441db5917a82a706c0561984d
container-native-virtualization/hco-bundle-registry@sha256:9380f4548497fb686d1a8e58b99e193642fbf3fb833ac7c057d22f65ca300757
container-native-virtualization/hostpath-csi-driver@sha256:f6b32695d5416d73c640191a8c17e2e4b0312b44a5a423df059f5dfcd1cb1b14
container-native-virtualization/hostpath-csi-driver-rhel8@sha256:f6b32695d5416d73c640191a8c17e2e4b0312b44a5a423df059f5dfcd1cb1b14
container-native-virtualization/hostpath-provisioner-rhel8@sha256:da6b5e2aafe2ca0c90a7748379e476fa027c34ffe0802a8d615390aa24b67c30
container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:3a8e1a34c6fc8c61fe2867801441bbb99577bf23d270b80d9caf52fb9b301f8d
container-native-virtualization/hyperconverged-cluster-operator@sha256:217a2b7ce56c29c1597e34ecb53bafc75e25fbcaede066d34626b8370de9aa1f
container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:a2404f404b881b29bc69d6c87192ad80534c6fa459dd9b659ba1fe7a49c8fa01
container-native-virtualization/kubemacpool@sha256:76602186ecc38db46cef56beb9a8c2bd4460be56794af636dd5c31d4026ba87a
container-native-virtualization/kubevirt-console-plugin@sha256:c46a2681478b2b03cddfe7e3cd8c184a018d061f6b30a11ec16c2d1a339adfea
container-native-virtualization/kubevirt-ssp-operator@sha256:dfcda07e27e4c170d08a4f91c37e54fc6a3cefdc5dace0c174d2b3657771b902
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:56b01b735ac16ab3518858e14cde99a06ad7aeab00cf4b6f9fe1395bcbc4b075
container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:8bd115404333e316023a9276c609e98ebb50772f92cffe1c4ea41653825c8c45
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:ca5741a9970f8945239638bfce8327214e390d35b9f37ca65b8b0a9f67299889
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:7de2998bfbaa885d59dd2797f4abcafd23ba73c4754046f4d36cc535a208499a
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:29dd6334a8d7f7e328414176b4b76a54fe71d142a563cbfe41e14c7086d7e907
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:797f91b01ab0d3c8634e2502bb38a59ccd4a196eb146f812336b679ea9394795
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:d674619099ea50b0010444c717f5b235caa55c743e7c3d165a8b7ea92d07b375
container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:e0945fc41e565da48e12731584d15c7f2c3ba390864d9f0d4283e7020aea08dc
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:e33643822bb0403125e84b990c920bf83e329e2cc2158126bf351f5b8295310b
container-native-virtualization/kubevirt-template-validator@sha256:bd57238bd8bab4b74ede39d4619c2363258b703b46e3d0ce2f1f2563a2bd4094
container-native-virtualization/libguestfs-tools@sha256:13b9e418907aae2a24f2588956bae8936b7eea3174c7f6a8ab26fabdefe6789c
container-native-virtualization/ovs-cni-marker@sha256:c98a610e7feb36b91480f630f485faed59de92ec2b83f009bb161724c5546b71
container-native-virtualization/ovs-cni-plugin@sha256:62b3c55916531e3f15bc6b7c7e23d25ee951aa5bfc7cca39eb2230505342d8d4
container-native-virtualization/virt-api@sha256:93cd133ce3b520e1365e7f3e855fa065009053da634b3175ea89b7b3852de221
container-native-virtualization/virt-artifacts-server@sha256:e7d532ecd8ec6ffac5444cd3c7a52fcd5e3e7f3dcd1df8d253a09d1971a65777
container-native-virtualization/virt-cdi-apiserver@sha256:60b1b9911b6e5434e0df8d32e6e5a5253c60ed0035be0fdf19155ba963eb397a
container-native-virtualization/virt-cdi-cloner@sha256:844f181d2178295f0014c61f570d959099376684918a7e1e2b9b9baa36224e2c
container-native-virtualization/virt-cdi-controller@sha256:30c7c5639f6d06bfb579946aee39d913ae3c06a3dfd41ef3657dc6b1c90d021d
container-native-virtualization/virt-cdi-importer@sha256:679acc2a33caf2a2fec4bb3a4f6c6344c632327b78f87d0b2bdb7fd8b967dd92
container-native-virtualization/virt-cdi-operator@sha256:3d6516ef93902ebacc730b995c13f4e09a498209212627cd3ec1630a5c06cdda
container-native-virtualization/virt-cdi-uploadproxy@sha256:51f4dfb6257d4a31f4d7fa7093b330d18e97dc08f0c00a1429af9d08d147a24a
container-native-virtualization/virt-cdi-uploadserver@sha256:893a3909583efab28a3ec59221a029d0d8bac5a923413e368e7c010516c5a352
container-native-virtualization/virt-controller@sha256:3925f5f45ae564fcb6672a3cd9d661590490ac28a3237bd3c64313e86e9adf42
container-native-virtualization/virt-handler@sha256:a691198c0f34cf18e214d9d9e53dd886437f21b2ca9c553eab91bdbdc668df53
container-native-virtualization/virt-launcher@sha256:2172f1e663e41b01f379ee68cd14d02586ae65a37a0755820c153c8003352770
container-native-virtualization/virt-operator@sha256:4db5f25c52cf499feae2eb99672638444ad9a7363445e76c77e7cfc17d448993
container-native-virtualization/virtio-win@sha256:804085ee9c9ffa452dd900f6f6546d2852e1c3d76fb8a64809ce720f49557a43
container-native-virtualization/vm-network-latency-checkup@sha256:916ee57840e408fbba468f054487d1d1fc88f99c38edc8e9318814cf7d87e7d1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility