Low: libguestfs security, bug fix, and enhancement update

Related Vulnerabilities: CVE-2022-2211  

Synopsis

Low: libguestfs security, bug fix, and enhancement update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libguestfs is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libguestfs packages contain a library used for accessing and modifying virtual machine disk images.

Security Fix(es):

  • libguestfs: Buffer overflow in get_keys leads to DoS (CVE-2022-2211)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 1674392 - No return values from a directory listing when there are simply too many files in that directory (NULL value return)
  • BZ - 1794518 - Rewrite libguestfs use of setfiles so that it doesn't stop on ext4 immutable bits
  • BZ - 1809453 - [RFE] Add support for LUKS encrypted disks with Clevis & Tang
  • BZ - 1844341 - The duplicate block device is listed when iface is set to 'virtio'
  • BZ - 1965941 - lvm-set-filter failed in guestfish with the latest lvm2 package
  • BZ - 2033247 - document encrypted RBD disk limitation
  • BZ - 2059285 - RFE: Rebase libguestfs to 1.48 in RHEL 9.1
  • BZ - 2065172 - SHA 1 signatures required to inspect packages in RHEL 6 guests [rhel-9.1.0]
  • BZ - 2084568 - Disable 5-level page tables when using -cpu max
  • BZ - 2086368 - Add Rocky Linux to list of REDHAT distros for code generation
  • BZ - 2097718 - Please build and ship php bindings to libguestfs
  • BZ - 2100862 - CVE-2022-2211 libguestfs: Buffer overflow in get_keys leads to DoS
  • BZ - 2117004 - RFE: Add support for Zstandard compression to guestfs_file_architecture API