🔒 Red Hat Security Advisory 🔒
📦 Product: OpenShift Virtualization
🆔 Advisory ID: RHSA-2023:4420-01
📅 Issue date: 2023-08-01
🔍 CVE Names: CVE-2023-24540
📜 Summary:
Red Hat OpenShift Virtualization release 4.12.5 is now available, featuring updates to packages and images that address various bugs and provide enhancements.
🛡️ Security Impact:
This update has been classified as "Important" by Red Hat Product Security. For detailed severity ratings, please check the Common Vulnerability Scoring System (CVSS) base score for each vulnerability using the provided CVE link(s) in the References section.
🎯 Relevant releases/architectures:
#CNV4 #RHEL7 #x86_64 #CNV4 #RHEL8 #x86_64
📝 Description:
OpenShift Virtualization is Red Hat's virtualization solution tailored for Red Hat OpenShift Container Platform.
This advisory contains OpenShift Virtualization 4.12.5 RPMs.
🔧 Security Fix(es):
CVE-2023-24540: golang: html/template: improper handling of JavaScript whitespace
For more information on the security issue(s), including the impact, CVSS score, acknowledgments, and other related details, please refer to the CVE page(s) listed in the References section.
💡 Solution:
To apply this update, including the changes described in this advisory, please follow the instructions at:
🔗 https://access.redhat.com/articles/11258
🐞 Bugs fixed:
- 2196027 - CVE-2023-24540 golang: html/template: improper handling of JavaScript whitespace
- 2227593 - Tracker for 4.12.5 RPM
📦 Package List:
CNV 4.12 for RHEL 7:
Source:
- kubevirt-4.12.5-1189.el7.src.rpm
x86_64:
- kubevirt-virtctl-4.12.5-1189.el7.x86_64.rpm
- kubevirt-virtctl-redistributable-4.12.5-1189.el7.x86_64.rpm
CNV 4.12 for RHEL 8:
Source:
- kubevirt-4.12.5-1189.el8.src.rpm
x86_64:
- kubevirt-virtctl-4.12.5-1189.el8.x86_64.rpm
- kubevirt-virtctl-redistributable-4.12.5-1189.el8.x86_64.rpm
🔗 References:
CVE-2023-24540: https://access.redhat.com/security/cve/CVE-2023-24540