Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0273 - Security Advisory
Issued:
2024-01-17
Updated:
2024-01-17

RHSA-2024:0273 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Virtualization 4.12.9 Images security and bug fix update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Virtualization release 4.12.9 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.12.9 images.

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.12 for RHEL 8 x86_64
  • Red Hat Container Native Virtualization 4.12 for RHEL 7 x86_64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • BZ - 2247667 - [4.12] Host assisted clone hangs because some provisioners don't allow mounting block PVC read only
  • CNV-34790 - [2247667] [4.12] Host assisted clone hangs because some provisioners don't allow mounting block PVC read only

CVEs

  • CVE-2007-4559
  • CVE-2022-3094
  • CVE-2022-4285
  • CVE-2022-40897
  • CVE-2022-44638
  • CVE-2022-48303
  • CVE-2022-48337
  • CVE-2022-48339
  • CVE-2022-48468
  • CVE-2023-2602
  • CVE-2023-2603
  • CVE-2023-4016
  • CVE-2023-4641
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-22745
  • CVE-2023-28321
  • CVE-2023-31486
  • CVE-2023-38546
  • CVE-2023-39325
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

x86_64

container-native-virtualization/bridge-marker@sha256:302f7b8ed01ed6fa7990507a8c8648af5a5607e6bb6dab8d8b2ce95c93c5a4d2
container-native-virtualization/cluster-network-addons-operator@sha256:0f32a09e0a6b9097102543b4a21c92d66679a7e9bd773b15d71fe4b1119f4579
container-native-virtualization/cnv-containernetworking-plugins@sha256:42eb5beab2327ff9263f3f43ab6b1fab8c8474676ff032823e3e9dc9af03ef15
container-native-virtualization/cnv-must-gather-rhel8@sha256:7cc48d1e0ef5d3ed1287d3ece0ac306e3eac1eaf283fe354eee905f721cba7d4
container-native-virtualization/hco-bundle-registry@sha256:a8cc033664e7c193f3ed7369924d467ef6caa27e734f683fd5eda4aaeb3f5d71
container-native-virtualization/hostpath-csi-driver@sha256:431eddb3927178f6a7b39b5b8937d4d39c7863bdfcd8227cd3e0b47af79c737d
container-native-virtualization/hostpath-provisioner-rhel8@sha256:844491b180e24c24ce6a1fc49cbef5399fbc044c544dbcbdf6a31c30f77c3235
container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:3cef15dbedca3ebb5f8e3ec1443344aadedaded73c3900334d4230d6819d4fed
container-native-virtualization/hyperconverged-cluster-operator@sha256:1c734396bbae0bd259cd3b5bdc1121323531d3a78ca5905d55ab14f092588104
container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:045151b2e55c0ba748b1ffe23e33cd3a230208bbf1b66ec2d514d9a73d6899b8
container-native-virtualization/kubemacpool@sha256:e8f9d6d66f03ee04a617ccfbc89b9f45f005cffa72106168bd402925fc3b3a8a
container-native-virtualization/kubevirt-console-plugin@sha256:4b6cd3523f8368c82f4be0fba90118491a3c5330e4f082551a9924c5b96aa290
container-native-virtualization/kubevirt-ssp-operator@sha256:1efc679921cd7fe1f191064d88d84cc057ca908b2daab88208e64911fe483159
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:fe19a7f39bb1b0da5f181391da7416a77280dd0c0492a1759de9f11fbced512a
container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:810016684887e31612770417cc14633f923202d5dc6215fa256a8a5bee92597b
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:944f1c609d14bdf705e3d76c7181f8e7ec25c309097aeafd843055f972b3aca5
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:8bd7f4eccdf2f54f7bf5b74a348c3a3eb2e7a75557f82b9f77db2b67dc1d6a24
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:4516d5b8ceda084f548d4f63d7597bf8094a73b81cbd37141ef530631cbb4ac9
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:223a95d2396f5f35fad5daab2f75b4c412020a03c7b7c117f1433f8f64509692
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:edf380ac51005edd536c828f1cb1b0d8a6795c68fffe5b4e0d545b83c10776b9
container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:3e3a9796a01fb606528231603c17a253854f6db1fd1ac5d5132f846d7d264dcd
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:caf5a64456741e60557f87440cbdf9a61305da07e9b42726517ff72e1041e3bb
container-native-virtualization/kubevirt-template-validator@sha256:9a2ffe17b78578d7a2a43974d553cde190689a792fef3394dbaffc0503310db7
container-native-virtualization/libguestfs-tools@sha256:207b0b99175a8264c623fefc959780941da4f143762c1962686d8c31d7c7f0da
container-native-virtualization/ovs-cni-marker@sha256:1543ee3d9b3cc4f8037f6924d48613d1cbda112455e484654d3b4a6f97f3116a
container-native-virtualization/ovs-cni-plugin@sha256:d943058669971f14a8e2a38387bc689ed1c0f8a34c749c2fbdab4122ff261bab
container-native-virtualization/virt-api@sha256:6331782585fd9c71d27d87fabf54583b56cbdb577c8826a97394956c08a2b457
container-native-virtualization/virt-artifacts-server@sha256:24c3dd085416026c64c4c6ca89c9b3c61625137f61ea281d19c32aaec67924b0
container-native-virtualization/virt-cdi-apiserver@sha256:50e2478a24a64d2a7e46d699475646efd92455228fe8ebcf648bfcbfe4e15a7e
container-native-virtualization/virt-cdi-cloner@sha256:6bb47b354ad8d30ff0820feadb644724956b313fed70051633a8e05cda32eff3
container-native-virtualization/virt-cdi-controller@sha256:4e5f797ff070d94646386c9feeaa03e157400d1dad201cf4bd134b6426dac319
container-native-virtualization/virt-cdi-importer@sha256:7d0811ccc983e9b875a7b9259654e22c98a645c41036a816d064ef84fea86eae
container-native-virtualization/virt-cdi-operator@sha256:a9489e302737cd6b453eb03e39c5d2f94fae6a25e3b42c73cd9c1a942ee72e5f
container-native-virtualization/virt-cdi-uploadproxy@sha256:449ef03e2ec6b468ecdc37679d7057083bb50d3923af7e141b6c3b44f8a006df
container-native-virtualization/virt-cdi-uploadserver@sha256:18d69db5be9c2acdc2c906c6103ca466e6d2001c97ccd8da5c70ba23b5366e59
container-native-virtualization/virt-controller@sha256:1caaf37a802ecdea65dff964c292e31a33fa119928edb7b57c4de7657315a989
container-native-virtualization/virt-exportproxy@sha256:b5834b9c826e7ea42600f350b3c4767a18f2c90d317f12d3f8956f201214a325
container-native-virtualization/virt-exportserver@sha256:85c866c4d48e4347f39eb23528ec8f75a2db0a16e1c754463ae66706d03348ef
container-native-virtualization/virt-handler@sha256:15e827877db2eb730dd3705f8a675769fd6f1adc5c1b9a84d8e1522ff39d47b7
container-native-virtualization/virt-launcher@sha256:34d7b05082cf585793d90d0decc684992ad7c4d992493fea9dcba50ee4249bac
container-native-virtualization/virt-operator@sha256:92853ab2214f111023bf23c6ac33264736463e113d0813e1389e8ad89668deff
container-native-virtualization/virtio-win@sha256:2ba15ef027ffef470e267cded5a3c087bd1942036920f85dbd06be68e4f59fb6
container-native-virtualization/vm-network-latency-checkup@sha256:c8a0fe956d24ba21ef5ade499ffc860c40dda98c6fabed4e5d81ed3bebc8ac1c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility