File _patchinfo of Package patchinfo.25861
<patchinfo incident="25861">
<issue tracker="cve" id="2022-1798"/>
<issue tracker="cve" id="2022-29162"/>
<issue tracker="cve" id="2022-1996"/>
<issue tracker="bnc" id="1200528">VUL-0: CVE-2022-1996: go-restful: CORS bypass</issue>
<issue tracker="bnc" id="1199460">VUL-0: CVE-2022-29162: runc: incorrect handling of inheritable capabilities in default configuration</issue>
<issue tracker="bnc" id="1199392">[kubevirt][Build137.1] missing required commands in virt-launcher image</issue>
<issue tracker="bnc" id="1199603">[kubevirt][Build137.1] Cannot get 'write' permission without 'resize': Image size is not a multiple of request alignment</issue>
<issue tracker="bnc" id="1202516">VUL-0: CVE-2022-1798: kubevirt: Arbitrary file read on the host from KubeVirt VMs</issue>
<packager>vulyanov</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container</summary>
<description>This update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container fixes the following issues:
The kubevirt stack was updated to version 0.54.0
Release notes https://github.com/kubevirt/kubevirt/releases/tag/v0.54.0
Security fixes:
- CVE-2022-1798: Fix arbitrary file read on the host from KubeVirt VMs (bsc#1202516)
Security fixes in vendored dependencies:
- CVE-2022-1996: Fixed go-restful CORS bypass bsc#1200528)
- CVE-2022-29162: Fixed runc incorrect handling of inheritable capabilities in default configuration (bsc#1199460)
- Fix containerdisk unmount logic
- Support topology spread constraints
- Update libvirt-go to fix memory leak
- Pack nft rules and nsswitch.conf for virt-handler
- Only create 1MiB-aligned disk images (bsc#1199603)
- Avoid to return nil failure message
- Use semantic equality comparison
- Drop kubevirt-psp-caasp.yaml
- Allow to configure utility containers for update test
- Symlink nsswitch.conf and nft rules to proper locations
- Drop unused package libvirt-client
- Install vim-small instead of vim
- Remove unneeded libvirt-daemon-driver-storage-core
- Install missing packages ethtool and gawk. Fixes bsc#1199392
</description>
</patchinfo>