Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:2060 - Security Advisory
Issued:
2024-04-25
Updated:
2024-04-25

RHSA-2024:2060 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Virtualization 4.14.5 Images security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Virtualization release 4.14.5 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.14.5 images.

Security Fix(es):

  • golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.14 for RHEL 9 x86_64

Fixes

  • BZ - 2268273 - CVE-2023-45288 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
  • CNV-39957 - [4.14] HPE (csi.hpe.com) now supports RWX/Block
  • CNV-35848 - Fix operator_health_impact label in VirtualMachineCRCErrors alert
  • CNV-40266 - CDI get stuck when DV source is blank and destination is lvms (block), breaking MTV imports from vmware
  • CNV-40627 - [4.14] Clone from snapshot: host assisted path creates wrong temporary restore PVC
  • CNV-40279 - secret persists even after the deletion of the virtual machine

CVEs

  • CVE-2023-4408
  • CVE-2023-5517
  • CVE-2023-5679
  • CVE-2023-6516
  • CVE-2023-45288
  • CVE-2023-50387
  • CVE-2023-50868
  • CVE-2024-0565
  • CVE-2024-1488
  • CVE-2024-26602

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

container-native-virtualization/bridge-marker-rhel9@sha256:b195227def41999c24ce08545ad44b24e7b73e1f1cae449059771889021365e2
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:eb70b77ceed22136afa7a2396414852d32adf029fa39781c0ffc27fddc18641f
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:1a1c15296c9dc8ded6915561aad06322ee3d7e0e3a553e5ed2cc1eda0ef6b736
container-native-virtualization/cnv-must-gather-rhel9@sha256:90bad38e33bfa1e04b5f39a26ec2c7a4f47f3c50321a8b13ac0c315e50478208
container-native-virtualization/hco-bundle-registry-rhel9@sha256:ed605b46162edaa361bfecefdda6813ed8b67d400c7d1f8e623b88b692ec95db
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:5e975c3d0747bcf52cddb6ffbee781de728c57c60bdc4ecb2a929c5a3a53817b
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:bc1156fb8f028be1945e4cdb9f287a5a11d205a79fa2953dc6bfc255faf524f2
container-native-virtualization/hostpath-provisioner-rhel9@sha256:08928889fa993ed89aa05040b27ec560b7ba7f5d090a486390646bee8d16f977
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:4bf255ba25a7ca9c3b3dab9d2e3b105213a264dde08544c0a0d48e1e8e1bf286
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:bb00bd53da4c120e049b5e899b31aa935b749c9a0a449408578b18882c1f7990
container-native-virtualization/kubemacpool-rhel9@sha256:e2623a16266ec70cb3b4b4acf4f69bbe53f34d18ad53a37f40225940e0324589
container-native-virtualization/kubesecondarydns-rhel9@sha256:6bcd09fad46e36de35550cb8213da1bd4b3e5e9274f8c6bc75583fdf0a656b63
container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:8fa75658260920f2210cec540d2635cf58fc5d5accad9e825541bee6e8a9a630
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:d9fe342cb788df0201453b8650aa04a5e5d55b6a3940ebb6edd5b33ad1d2570b
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:a8705583c07648fb5498454c8289cd75204ca6bb90302f855ee6222784427bb4
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:491dfef99e2b3196539a29a2065e857ab3b28012f0cffd3567f75a55dff81a5e
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:03bf1dc8ac9bce13f7031b6d20c9cd664c7b4ee1f9c06e7a0e4737af54006380
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:7104bb01c82cd031a30f00efe7bab48210859c1079f8be6a048c91ecc34c264e
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:8b669fd418829f963f779dc172616137753fa139e8ea8c3d6d15646d9f6e8c63
container-native-virtualization/libguestfs-tools-rhel9@sha256:168cbbf3a63fcb310d4be9007ddb5410ca331e3c0d34c64551ca1b1f11ed067f
container-native-virtualization/mtq-controller-rhel9@sha256:0604e2eb630ee1eac352a195818e7cb4a3240ac03eb6d134cabb4683cb139193
container-native-virtualization/mtq-lock-server-rhel9@sha256:a9dd4d71eae0fa09331e5e6a353624e2ddb3ec9877dfa7dc08be989e2adcb71c
container-native-virtualization/mtq-operator-rhel9@sha256:f08fac06f09745fc08831602d05bc3d723982c451f28cbc384da1270fbd94cf9
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:823611e324dac409e3ffd30d64c1affcdeb446e2dcc3966d4465f65fc22ce0e5
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:f17a8110c748c8ffabe93efc3c6443a3b476616eaa01dbdac0c37ed780713f13
container-native-virtualization/pr-helper-rhel9@sha256:482a71b7821e07648acf929298907292370c57c4d3bc30c467538abe43559a7e
container-native-virtualization/virt-api-rhel9@sha256:eefd8e5eb2012c46816b0a8526e494bbcb959c646fdbd7aa52ee89ca2fd06c72
container-native-virtualization/virt-artifacts-server-rhel9@sha256:2ec918c4ad51e3650c5885ec2f4db33a14e0078a1bfc11451437dd6244abe57c
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:8ec1b24067abb40f6e564563eda4d239b2039783cdb2394b4bd2f7ca73ba6cea
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:407f096eb2369cd6b4af6d7c77db2861b01ceef5e970a511a88a185eef6840d3
container-native-virtualization/virt-cdi-controller-rhel9@sha256:b6c7c8093b64e4c6754f8aa2bae59c05eef755c5c831f8d8985e7446e8fdc892
container-native-virtualization/virt-cdi-importer-rhel9@sha256:f1fd2c602714ef0dd021fe52aa65b975e9805a0d9477f127eab17bf2d6156af2
container-native-virtualization/virt-cdi-operator-rhel9@sha256:e237f8c02899763fb7b8bbf0f13171b51fc5a543ec033d5a111c7d2d244214b0
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:89e3135602086f04cb00ddae64cd433b3c73f769f5ef654bb5250d9d1af3ed21
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:b189b3b120e3698af126b156e41312e967db968aeaf046b78a5a833930bc850e
container-native-virtualization/virt-controller-rhel9@sha256:e3a5beeeb3e8d5b854891b4369453a11892203ba4f5b952123aea249584a2cef
container-native-virtualization/virt-exportproxy-rhel9@sha256:a63a5ab663facf4ee56ec14b19a94a88ed14da38f3a760cace16c029e02db27c
container-native-virtualization/virt-exportserver-rhel9@sha256:b251fe9dd78413eebff9133e80d39238703e2b3e503959e2cf96b2ac0e732c06
container-native-virtualization/virt-handler-rhel9@sha256:66d77e7ff0f7b4cdc55bb3cdfe65a36cfc247c87e4fed86e8784ddc4815ba48b
container-native-virtualization/virt-launcher-rhel9@sha256:777e3e5e4a1edce5803b4b631ed9b75892ea198b809fe4403409a39c2a1c5585
container-native-virtualization/virt-operator-rhel9@sha256:796faebcd97b34c762499fcb019246fabe0319a34acf3fd0a45b2385bd79081b
container-native-virtualization/virtio-win-rhel9@sha256:5b1308fd374ab648ba70284a2fd26518dfcc672cca6e1ffa42928b1e73b7f268
container-native-virtualization/vm-console-proxy-rhel9@sha256:7921da0f8c00d3584eed5ab5cda27593accfddd5a0533712f5d338b254a92097
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:19227650fd86ad8388578b876ea136058cf81e88cb62759259ad3d631b731400

x86_64

container-native-virtualization/bridge-marker-rhel9@sha256:126f16e2903c77db72f3073e463fe3e33001cb393215b55afa56de94faad17c0
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:060d15b6a00a6f1ed5fd886467378d80ab232e4012ce33ffaa5843730b03be7e
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:d6316a5f0229d924fb2859a89074808979c8ed9dff7d6b71d4750c6aaff00d41
container-native-virtualization/cnv-must-gather-rhel9@sha256:a9120cb7a5f374fafea5692a5093a201ee1eb414df9bedddad98f2117f1521a5
container-native-virtualization/hco-bundle-registry-rhel9@sha256:1134d3ce149f5b64bfca52a4e3d38a0b7864e6631b3edfc34c0592aa2ccb0b8e
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:d9a503464046f5357fb58d484c5ca4424a45b319417488f906ff892ee45dc491
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:914db4c900771b40b21c7a80993efbafa8b9d2b4002b46a58e8498f8c26ccb9c
container-native-virtualization/hostpath-provisioner-rhel9@sha256:c2dd6139eab4fe9cb0af485ed68a42890a883f58f5c81f5ce169dfcd54667663
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:936b3ace24072b9bf4f1c2008b236a92a3fe08c0749823e94daa5ffabbcd7848
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:3e62bb92d18561675c80d5e2f720153e1a82300edb6d37c4a824cbdd46fa8b83
container-native-virtualization/kubemacpool-rhel9@sha256:d070efdb15fb0bfcb20f9e888cc28bc858a0088e6e9e969992480ddac1452bca
container-native-virtualization/kubesecondarydns-rhel9@sha256:acc13d82ab22b2c46f74ccc0c83e154ed46047ee3b9771bf7bf8f8f21eb1a145
container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:33161895d85eb64e8b756d486c3083fbe6c32036421296c6234d4940971a6487
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:c87ea56b6e99e0ef34b2a8445aff7d7fdec5842f02a4c8001b4140a67111774a
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:3ebe33bac9e801ded32791295acc9596430bf4f4a55be1745fda4a137e02f5c6
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:b1036e603c36b05cf27368ba0cd7e1a6318f28e51e9565505b6d0b77004ee9d5
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:effa00c2d39b9b3501ed42c5f38c2f85d6090ad9a3037b2e5ea8953cdc1dc47a
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:a59412be5545a263dcb93adaa2c3eaf9b979ffb0da87e688778fc2cde6a3d716
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:5fd34ba0778fef7fd8b1648d525b8d03bc75fb7d8a2b29f9e8929fae142a4126
container-native-virtualization/libguestfs-tools-rhel9@sha256:bbac4e77c2ed9188c94866004f74bf26894e4a456463b4548256e50b678740b7
container-native-virtualization/mtq-controller-rhel9@sha256:ca22d241fe43af4a45e4b9176c5aaf75327f5b1f16691d82885ac553de3667ed
container-native-virtualization/mtq-lock-server-rhel9@sha256:58cc012f441ece150f0398a7a7a165d8c499d029ba8cdc2664b3516072269a8d
container-native-virtualization/mtq-operator-rhel9@sha256:711a6137057ff635192dea73b9424e6a2f95d0f229f0cdf09c7a16c36ba59370
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:144a67d9c708c0d226afdcbdbb76234f2715f3809e37792a43d31af4b5b99372
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:a5b2a6b41a0120f9a1d95e1529a2200e88849f161b5b458022bfae767966f475
container-native-virtualization/pr-helper-rhel9@sha256:09fae9412de92a7d8a8bdab844371ac30232daf1f74563016ecf72287a890f8b
container-native-virtualization/virt-api-rhel9@sha256:855131ed1ee02f7a20bca554be17d48f308e001623c3c9050d584306f84e7bff
container-native-virtualization/virt-artifacts-server-rhel9@sha256:d5f8c88a1d72862115113b95ad89ad9cf53564103ce889fb2b654cbc5fc515f6
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:292a72a521a6d46b13676f0541836554b430271cd1669006236183fb614344d8
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:a08b4400febe97442ee9e5233cbc356f52a1ea4b0cd483a6de790afe4d3d8562
container-native-virtualization/virt-cdi-controller-rhel9@sha256:a4a5fe633ceba525a4dd17a96ff4674a35bfa1bbd32b80c0de22d92c565d88fe
container-native-virtualization/virt-cdi-importer-rhel9@sha256:62faac2d2e82fddf225d2c2f2432f833b6c948c774da16c5a54bc7c3599ba3b4
container-native-virtualization/virt-cdi-operator-rhel9@sha256:721a7dcf7e5a908eba26ecc603ad7ee4509d1ead3d977148194e0a9910ec8bb0
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:50f601eb636afd53759698edbce79dfb0fde74b9b1c2f36970013d57c3e9b4f7
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:6511b03ad620156005369b94d02cadd306103334cf51547fcb1a5743de5baf35
container-native-virtualization/virt-controller-rhel9@sha256:3d2947e853e5619684623ed7e0b73d84b3e0278ddf970dafdffda022613e06ce
container-native-virtualization/virt-exportproxy-rhel9@sha256:66e06e4a600a860f0d954cf43d622b65e4f98d99b5d949a985d18030af4bfa02
container-native-virtualization/virt-exportserver-rhel9@sha256:fe61a766f1ead53002208eef8672824f36da861c65f82e3b8215f4097779aed5
container-native-virtualization/virt-handler-rhel9@sha256:c6e7c7710c4c254bbffccf1226d311e91913491ced31e2d5f4e4493d3c53b992
container-native-virtualization/virt-launcher-rhel9@sha256:e4c6a1eb9ac8eee15487079aa2d721efda2390135917e884b7cd82792653d345
container-native-virtualization/virt-operator-rhel9@sha256:4affe993611a28b0b42b01102ee6af0e1ca12f70bbe79f4ff96da4063729e809
container-native-virtualization/virtio-win-rhel9@sha256:751be111b562a5a3aa34671f7a095bae50d44091fc504499ee874cc7fea2a605
container-native-virtualization/vm-console-proxy-rhel9@sha256:74751213289932893a464d459e9e2d87ee65f3cc6406134273d71ed343974e27
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:c5d7d560f97040008743996d70e3ad63e7860add658ca6c27313e28f73dacbc1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility