This bug was created to ensure that one or more security vulnerabilities are fixed in affected versions of oVirt. For comments that are specific to the vulnerability please use bugs filed against the "Security Response" product referenced in the "Blocks" field.
As of february 21, 2022 CentOS Stream includes kernel-4.18.0-365.el8 (https://koji.mbox.centos.org/koji/buildinfo?buildID=21111) which contains the fix: - drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047602] {CVE-2022-22942}
*** Bug 2056599 has been marked as a duplicate of this bug. ***
ISO: https://resources.ovirt.org/pub/ovirt-4.4/iso/ovirt-node-ng-installer/4.4.10-2022030308/el8/ovirt-node-ng-installer-4.4.10-2022030308.el8.iso