You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Virtualization

Sigurnosni nedostaci programskog paketa Virtualization

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LRH

Hash: SHA256

Red Hat Security Advisory

Synopsis: Moderate: Red Hat Virtualization security and bug fix update
Advisory ID: RHSA-2018:3470-01
Product: Red Hat Virtualization
Advisory URL:
Issue date: 2018-11-05
CVE Names: CVE-2018-10858 CVE-2018-10873 CVE-2018-10904
CVE-2018-10907 CVE-2018-10911 CVE-2018-10913
CVE-2018-10914 CVE-2018-10923 CVE-2018-10926
CVE-2018-10927 CVE-2018-10928 CVE-2018-10929
CVE-2018-10930 CVE-2018-14652 CVE-2018-14653
CVE-2018-14654 CVE-2018-14659 CVE-2018-14660

1. Summary:

An update for imgbased, redhat-release-virtualization-host, and
redhat-virtualization-host is now available for Red Hat Virtualization 4
for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

RHEL 7-based RHEV-H for RHEV 4 (build requirements) – noarch, x86_64
Red Hat Virtualization 4 Hypervisor for RHEL 7 – noarch

3. Description:

The redhat-virtualization-host packages provide the Red Hat Virtualization
Host. These packages include redhat-release-virtualization-host,
ovirt-node, and rhev-hypervisor. Red Hat Virtualization Hosts (RHVH) are
installed using a special build of Red Hat Enterprise Linux with only the
packages required to host virtual machines. RHVH features a Cockpit user
interface for monitoring the host’s resources and performing administrative

Security Fix(es):

* spice: Missing check in allows
for buffer overflow and denial of service (CVE-2018-10873)

* glusterfs: Multiple flaws (CVE-2018-10904, CVE-2018-10907,
CVE-2018-10923, CVE-2018-10926, CVE-2018-10927, CVE-2018-10928,
CVE-2018-10929, CVE-2018-10930, CVE-2018-10911, CVE-2018-10914,
CVE-2018-14652, CVE-2018-14653, CVE-2018-14654, CVE-2018-14659,
CVE-2018-14660, CVE-2018-14661, CVE-2018-10913)

* samba: Insufficient input validation in libsmbclient (CVE-2018-10858)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Red Hat would like to thank Michael Hanselmann ( for reporting
CVE-2018-10904, CVE-2018-10907, CVE-2018-10923, CVE-2018-10926,
CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930,
CVE-2018-10911, CVE-2018-10914, CVE-2018-14652, CVE-2018-14653,
CVE-2018-14654, CVE-2018-14659, CVE-2018-14660, CVE-2018-14661, and
CVE-2018-10913. The CVE-2018-10873 issue was discovered by Frediano Ziglio
(Red Hat).

Bug Fix(es):

* When upgrading Red Hat Virtualization Host (RHVH), imgbased fails to run
garbage collection on previous layers, so new logical volumes are removed,
and the boot entry points to a logical volume that was removed.

If the RHVH upgrade finishes successfully, the hypervisor boots
successfully, even if garbage collection fails. (BZ#1632058)

* During the upgrade process, when lvremove runs garbage collection, it
prompts for user confirmation, causing the upgrade process to fail. Now the
process uses “lvremove –force” when trying to remove logical volumes and
does not fail even if garbage collection fails, and as a result, the
upgrade process finishes successfully. (BZ#1632585)

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

5. Bugs fixed (

1501276 – RHVH 4.2 should include RHGS 3.4 Batch #1 packages
1593731 – [downstream clone – 4.2.7] Rpm verify fails for newly installed libvirt-daemon-config-nwfilter package .
1596008 – CVE-2018-10873 spice: Missing check in allows for buffer overflow and denial of service
1601298 – CVE-2018-10904 glusterfs: Unsanitized file names in debug/io-stats translator can allow remote attackers to execute arbitrary code
1601642 – CVE-2018-10907 glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code
1601657 – CVE-2018-10911 glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory
1607617 – CVE-2018-10914 glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c
1607618 – CVE-2018-10913 glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c
1610659 – CVE-2018-10923 glusterfs: I/O to arbitrary devices on storage server
1612658 – CVE-2018-10927 glusterfs: File status information leak and denial of service
1612659 – CVE-2018-10928 glusterfs: Improper resolution of symlinks allows for privilege escalation
1612660 – CVE-2018-10929 glusterfs: Arbitrary file creation on storage server allows for execution of arbitrary code
1612664 – CVE-2018-10930 glusterfs: Files can be renamed outside volume
1612805 – CVE-2018-10858 samba: Insufficient input validation in libsmbclient
1613143 – CVE-2018-10926 glusterfs: Device files can be created in arbitrary locations
1613231 – goferd errors in /var/log/messages of Red Hat Virtualization Host
1614971 – Upgrading RHV-H from 4.0.X to 4.2 is failing during migrate_var
1619590 – Rebase RHV-H on RHEL 7.6
1624453 – Host “hostname” moved to Non-Operational state as host does not meet the cluster’s minimum CPU level. Missing CPU features : ssbd, spec_ctrl
1626960 – [el7.6]Network parameters IPv4/route/ovirtmgmt are missing during deploying Hosted-Engine
1631576 – CVE-2018-14654 glusterfs: “features/index” translator can create arbitrary, empty files
1632585 – lvremove command will fail if it asks for confirmation while removing old RHV-H layers
1632974 – CVE-2018-14652 glusterfs: Buffer overflow in “features/locks” translator allows for denial of service
1633431 – CVE-2018-14653 glusterfs: Heap-based buffer overflow via “gf_getspec_req” RPC message
1635926 – CVE-2018-14660 glusterfs: Repeat use of “GF_META_LOCK_KEY” xattr allows for memory exhaustion
1635929 – CVE-2018-14659 glusterfs: Unlimited file creation via “GF_XATTR_IOSTATS_DUMP_KEY” xattr allows for denial of service
1636880 – CVE-2018-14661 glusterfs: features/locks translator passes an user-controlled string to snprintf without a proper format string resulting in a denial of service

6. Package List:

Red Hat Virtualization 4 Hypervisor for RHEL 7:



RHEL 7-based RHEV-H for RHEV 4 (build requirements):




These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from

7. References:

8. Contact:

The Red Hat security contact is <>. More contact
details at

Copyright 2018 Red Hat, Inc.
Version: GnuPG v1


RHSA-announce mailing list

AutorToni Vugdelija
Cert idNCERT-REF-2018-11-0001-ADV
More in Preporuke
Sigurnosni nedostatak programskog paketa network-manager

Otkriven je sigurnosni nedostatak u programskom paketu network-manager za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja...