Bug 1831544 (CVE-2020-10731)
| Summary: | CVE-2020-10731 openstack-tripleo-heat-templates: No sVirt protection for OSP16 VMs due to disabled SELinux | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | alee, cjeanner, dbecker, egallen, eglynn, emilien, hrybacki, jagee, jhakimra, jjoyce, jpichon, jschluet, kbasil, kchamart, lbezdick, lhh, lpeer, lyarwood, mburns, morazi, nkinder, ntait, pbabbar, pkopec, pweeks, rhayakaw, rhos-maint, rmascena, sclewis, scohen, security-response-team, slinaber, slong, tsedovic |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | openstack-tripleo-heat-templates 11.3.2, openstack-tripleo-heat-templates 10.6.3 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-07-29 07:27:47 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1831827, 1850811, 1851117, 1861403 | ||
| Bug Blocks: | 1822260 | ||
|
Description
Dhananjay Arunesh
2020-05-05 08:26:09 UTC
Acknowledgments: Name: Lukas Bezdicka (Red Hat), Daniel Berrangé (Red Hat) External References: https://bugs.launchpad.net/tripleo/+bug/1880947 Created openstack-tripleo-heat-templates tracking bugs for this issue: Affects: openstack-rdo [bug 1861403] This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2020:3199 https://access.redhat.com/errata/RHSA-2020:3199 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-10731 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.0 (Train) Via RHSA-2020:3406 https://access.redhat.com/errata/RHSA-2020:3406 This issue has been addressed in the following products: Red Hat OpenStack Platform 15.0 (Stein) Via RHSA-2020:3410 https://access.redhat.com/errata/RHSA-2020:3410 |