Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10758 - Security Advisory
Issued:
2024-12-03
Updated:
2024-12-03

RHSA-2024:10758 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Virtualization 4.12.15 Images

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Virtualization release 4.12.15 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.12.15 images.

Security Fix(es):

  • net/http: Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.12 for RHEL 8 x86_64

Fixes

  • BZ - 2295310 - CVE-2024-24791 net/http: Denial of service due to improper 100-continue handling in net/http

CVEs

  • CVE-2023-45235
  • CVE-2024-3596
  • CVE-2024-5535
  • CVE-2024-24791

References

  • https://access.redhat.com/security/updates/classification/#moderate

x86_64

container-native-virtualization/bridge-marker@sha256:f1113575071801592b008aba2e48170438a7c3545eff89fc542c9fd447e83ba3
container-native-virtualization/cluster-network-addons-operator@sha256:0b8536a261764cb6c97f344f6d6c463677077e71b6b45493cab84bf7e943edb9
container-native-virtualization/cnv-containernetworking-plugins@sha256:73f773ae0f85360df8e4a933771017543985ae95e3b6846bd815dd841ae459f4
container-native-virtualization/cnv-must-gather-rhel8@sha256:0a12263f5cda908c1b8c7c373a4c1764b85c02d760c03e403efb7e2c9ff2f537
container-native-virtualization/hco-bundle-registry@sha256:066b34c68d1441dbe686b5d42dac12ee912f12e60934cd7c7a315b2b7edda2c9
container-native-virtualization/hostpath-csi-driver@sha256:c3d0a40423bfdb3c65a5bed67e6d2a2a1d61ad0c59480773e65b67b18b2858fe
container-native-virtualization/hostpath-provisioner-rhel8@sha256:9c0f785c5152746bce503e1cd4dbd02d6b1b77a045c9b6a46148a7a0105b528e
container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:e70e2745b2580c67cd1d1514d2d92e415a45e97508e34449671a7e4dd9d67fd8
container-native-virtualization/hyperconverged-cluster-operator@sha256:198dfe264298977874c0c08f97ec2ae9c7bfb529ff9f9e034c827d899dc5fb33
container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:f89db14d1a951d2b19586a4b76e354c114a8c435e74f492de8cda3ec8ec16fa8
container-native-virtualization/kubemacpool@sha256:003e7f25d41c3f2778a1f0e302bfd7d494c7ebe47b3670764d3b12564a04a111
container-native-virtualization/kubevirt-console-plugin@sha256:cc438c5e1b4af9bec41c9f5d59d38d6bd80b6687759d13ce829a5e9af765441b
container-native-virtualization/kubevirt-ssp-operator@sha256:215c5087356114c6cd18d41e2d1f77956a1020b57ab111d1661cf40d00020faf
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:9b401d598a7ebda5f008509d45b6914e8d7cf0d40dbaf2aebba35919ea35607e
container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:cbe72f074391c0e15c0d923bad664fd247d4187ee3061abd81c5dd31229a7faa
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:9b55a9637b64fe1f87c4099cade7217bae7e6942b975a5269a52cb52b89366f9
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:88537e6dfb4ca1ce326d8d8c1fec23b6f636ffbf15ea7aa1b12c91582fd8ed82
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:f86bde9d8409fdf966530baeb58018775b933fea71a4f26b10ff955b4c9ece02
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:9eca3887353841fdd63ab9dd91dcd3a1edcce36f6805f4317ed542b84174fe11
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:c1ffbfaaceee9654455312bd7ee41457238a9bbb446065317aa8c2c09174ac50
container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:9359e4041cbf051dd67376c40c18deadf3544cf1f29502a863e919b0361b1654
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:c60a5f0d2e6cdab9209981b62358111e5d848fc8f97702b98faed3e5893698e5
container-native-virtualization/kubevirt-template-validator@sha256:01d99c961937139fb25fa1d539d8b48bd20c4e0c39852fb9b0516657438c5b2b
container-native-virtualization/libguestfs-tools@sha256:9b1118f3c3da72b1b931c4fb3dc9106075399585c974a359fb3cdecf1c71a91e
container-native-virtualization/ovs-cni-marker@sha256:efadea176105da1674b84def29d40810fad037bf9b4ac7c4be69c210d4071c74
container-native-virtualization/ovs-cni-plugin@sha256:f94ac4f1965737b4a891b4e8928c1cb5079b7ad3bfceea05d98cf9dbf3ffe319
container-native-virtualization/virt-api@sha256:ce33568af0772b25561000cdfc4a6c29863096f2172abc64d0268f7cadca59f8
container-native-virtualization/virt-artifacts-server@sha256:4a1957741d6bcb67deaa4913a4883dd4aa88ee84b8e9cdaabff7c975c60fce20
container-native-virtualization/virt-cdi-apiserver@sha256:f4f98d2b7d868844b1946f8d31752a62fe31209887105d3704ceb6bb6229209c
container-native-virtualization/virt-cdi-cloner@sha256:a1eb9cd7bebbd815a12e11ba6dad497d4de4310a6cadb688018028d4b7b5d799
container-native-virtualization/virt-cdi-controller@sha256:1f61a2b5c8a2e17d5e8fc193888760cd4d2b3e0a6ff8ea0112baab3ce5427a6f
container-native-virtualization/virt-cdi-importer@sha256:7492e0513e69f9c20d1d686fd565ea8d9b2f923ab74a30a9398e3b42ac8d1691
container-native-virtualization/virt-cdi-operator@sha256:4a99967fb51f4eda2a8c955686e2094b0234dba3e2746752507d730a73118c03
container-native-virtualization/virt-cdi-uploadproxy@sha256:b4da629c0a10985a21f52f4736bcdfe745e78ff01be8a9146d420bd134a126ae
container-native-virtualization/virt-cdi-uploadserver@sha256:12bca90a5a7df628d7952215d3fbccdd1238ce1d08d2c0a2a244a32d6da813d6
container-native-virtualization/virt-controller@sha256:c769b847818688e3aeb94ebefb204ea65a15f1369a6309e14cb398fc85a57208
container-native-virtualization/virt-exportproxy@sha256:3504076518fbcd2c15018fd961b925a06b2ab1fdc8be2111d63a7eb5e7cf94e4
container-native-virtualization/virt-exportserver@sha256:3fb4fa139bfdd8320cba6f9efea8338728e2610ce010d90b79bec68fb8fad5e2
container-native-virtualization/virt-handler@sha256:1550a1c1c09e4f2a1bce7d8c4514fe32b97521586479ffa671be7abd54b47356
container-native-virtualization/virt-launcher@sha256:16d991f4de79ccf48522cd15f941a7faffc51bb20b2ca802edc4204bc2c43d19
container-native-virtualization/virt-operator@sha256:34f2ae8e2980910d09c6f3ba3c93b5af81b6b1131b41a146b1fef6cb90ce3ee2
container-native-virtualization/virtio-win@sha256:e7f5976400020d28968915a4dff0d55ec21780e88b50bca6ab64473f2634a895
container-native-virtualization/vm-network-latency-checkup@sha256:668a7b44e0518de7b2986a8b5ce1156f8e2b8dc3de9e21da2e9726866046cef3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility