File _patchinfo of Package patchinfo.25865

<patchinfo incident="25865">
  <issue tracker="cve" id="2022-1798"/>
  <issue tracker="cve" id="2022-1996"/>
  <issue tracker="cve" id="2022-29162"/>
  <issue tracker="bnc" id="1199603">[kubevirt][Build137.1] Cannot get 'write' permission without 'resize': Image size is not a multiple of request alignment</issue>
  <issue tracker="bnc" id="1200528">VUL-0: CVE-2022-1996: go-restful: CORS bypass</issue>
  <issue tracker="bnc" id="1199392">[kubevirt][Build137.1] missing required commands in virt-launcher image</issue>
  <issue tracker="bnc" id="1199460">VUL-0: CVE-2022-29162: runc: incorrect handling of inheritable capabilities in default configuration</issue>
  <issue tracker="bnc" id="1202516">VUL-0: CVE-2022-1798: kubevirt: Arbitrary file read on the host from KubeVirt VMs</issue>
  <packager>vulyanov</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container</summary>
  <description>This update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container fixes the following issues:

Security issues fixed:

- CVE-2022-1798: Fix arbitrary file read on the host from KubeVirt VMs (bsc#1202516)

Security issues fixed in vendored dependencies:

- CVE-2022-1996: Fixed go-restful CORS bypass (bsc#1200528)
- CVE-2022-29162: Fixed runc incorrect handling of inheritable capabilities in default configuration (bsc#1199460)

Other fixes:

- Pack nft rules and nsswitch.conf for virt-handler
- Only create 1MiB-aligned disk images (bsc#1199603)
- Avoid to return nil failure message
- Use semantic equality comparison
- Allow to configure utility containers for update test
- Install nftables to manage network rules
- Install tar to allow kubectl cp ...
- Symlink nsswitch.conf and nft rules to proper locations
- Enable USB redirection support for QEMU
- Install vim-small instread of vim
- Drop libvirt-daemon-driver-storage-core
- Install ethtool and gawk (bsc#1199392)
- Use non-versioned appliance to avoid redundant rpm query
- Explicitly state the dependency on kubevirt main package
</description>
</patchinfo>
openSUSE Build Service is sponsored by