openSUSE-SU-2021:2274-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:2274-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2021:2274-1
Related
Published
2021-07-11T07:30:34Z
Modified
2021-07-11T07:30:34Z
Summary
Security update for kubevirt
Details

This update for kubevirt fixes the following issues:

General:

  • Updated kubevirt to version 0.40.0
  • Fixed an issue when calling virsh-domcapabilities
  • Fixed the the wrong registry path for containers.

Security fixes:

  • CVE-2021-20286: A flaw was found in libnbd 1.7.3. An assertion failure in nbdunlockedopt_go in ilb/opt.c may lead to denial of service.
References

Affected packages

openSUSE:Leap 15.3 / kubevirt

Package

Name
kubevirt
Purl
pkg:rpm/opensuse/kubevirt&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.40.0-5.11.2

Ecosystem specific

{
    "binaries": [
        {
            "kubevirt-virt-controller": "0.40.0-5.11.2",
            "kubevirt-virt-handler": "0.40.0-5.11.2",
            "kubevirt-virt-api": "0.40.0-5.11.2",
            "kubevirt-tests": "0.40.0-5.11.2",
            "kubevirt-virt-launcher": "0.40.0-5.11.2",
            "kubevirt-virt-operator": "0.40.0-5.11.2",
            "kubevirt-manifests": "0.40.0-5.11.2",
            "kubevirt-virtctl": "0.40.0-5.11.2",
            "kubevirt-container-disk": "0.40.0-5.11.2"
        }
    ]
}