Bug 2065579
Summary: | CVE-2022-25235 CVE-2022-25236 CVE-2022-25315 expat: various flaws [ovirt-4.5] | ||
---|---|---|---|
Product: | [oVirt] ovirt-node | Reporter: | Sandro Bonazzola <sbonazzo> |
Component: | Included packages | Assignee: | Sandro Bonazzola <sbonazzo> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | cshao <cshao> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 4.4.10.2 | CC: | arachman, bugs, cshao, lsvaty, lveyde, mavital, peyu, sanja, sbonazzo, weiwang, yaniwang |
Target Milestone: | ovirt-4.5.0 | Keywords: | Security, SecurityTracking |
Target Release: | 4.5.0 | Flags: | sbonazzo:
ovirt-4.5+
cshao: testing_ack+ |
Hardware: | Unspecified | ||
OS: | Unspecified | ||
URL: | https://koji.mbox.centos.org/koji/packageinfo?packageID=26 | ||
Whiteboard: | |||
Fixed In Version: | expat-2.2.5-6 | Doc Type: | Release Note |
Doc Text: |
oVirt Node includes updated expat package providing fixes for multiple CVEs:
[CVE-2022-25315](https://bugzilla.redhat.com/show_bug.cgi?id=2056363)
[CVE-2022-25235](https://bugzilla.redhat.com/show_bug.cgi?id=2056366)
[CVE-2022-25236](https://bugzilla.redhat.com/show_bug.cgi?id=2056370)
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-04-20 06:33:59 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | Node | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2057012, 2057035, 2057125, 2065582 | ||
Bug Blocks: | 2056363, 2056366, 2056370 |
Description
Sandro Bonazzola
2022-03-18 09:02:54 UTC
expat-2.2.5-8.el8 (https://koji.mbox.centos.org/koji/buildinfo?buildID=21436) shipped to CentOS Stream 8 and is already on mirrors: http://mirror.centos.org/centos/8-stream/BaseOS/x86_64/os/Packages/expat-2.2.5-8.el8.x86_64.rpm Test version: ovirt-node-ng-installer-4.5.0-2022040605.el8.iso ovirt-node-ng-4.5.0-0.20220406.0+1 expat-2.2.5-8.el8.x86_64 #rpm -qa | grep expat expat-2.2.5-8.el8.x86_64 ovirt-node includes the correct expat package, so the bug is fixed, change bug status to VERIFIED. This bugzilla is included in oVirt 4.5.0 release, published on April 20th 2022. Since the problem described in this bug report should be resolved in oVirt 4.5.0 release, it has been closed with a resolution of CURRENT RELEASE. If the solution does not work for you, please open a new bug report. |