This bug was created to ensure that one or more security vulnerabilities are fixed in affected versions of oVirt. For comments that are specific to the vulnerability please use bugs filed against the "Security Response" product referenced in the "Blocks" field.
RHEL has been reported not affected so as fallback CentOS Stream and oVirt Node are not affected as well. Closing Not A Bug