Rocky Linux 8 : virt:rhel and virt-devel:rhel (RLSA-2022:7472)

medium Nessus Plugin ID 184779

Synopsis

The remote Rocky Linux host is missing one or more security updates.

Description

The remote Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2022:7472 advisory.

- A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory. (CVE-2021-3507)

- A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd). (CVE-2022-0897)

- A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor. (CVE-2022-2211)

- swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds. (CVE-2022-23645)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://errata.rockylinux.org/RLSA-2022:7472

https://bugzilla.redhat.com/show_bug.cgi?id=1519071

https://bugzilla.redhat.com/show_bug.cgi?id=1851227

https://bugzilla.redhat.com/show_bug.cgi?id=1951118

https://bugzilla.redhat.com/show_bug.cgi?id=1985827

https://bugzilla.redhat.com/show_bug.cgi?id=2028823

https://bugzilla.redhat.com/show_bug.cgi?id=2029980

https://bugzilla.redhat.com/show_bug.cgi?id=2051332

https://bugzilla.redhat.com/show_bug.cgi?id=2056491

https://bugzilla.redhat.com/show_bug.cgi?id=2060843

https://bugzilla.redhat.com/show_bug.cgi?id=2062610

https://bugzilla.redhat.com/show_bug.cgi?id=2062611

https://bugzilla.redhat.com/show_bug.cgi?id=2063883

https://bugzilla.redhat.com/show_bug.cgi?id=2066828

https://bugzilla.redhat.com/show_bug.cgi?id=2067118

https://bugzilla.redhat.com/show_bug.cgi?id=2067126

https://bugzilla.redhat.com/show_bug.cgi?id=2069946

https://bugzilla.redhat.com/show_bug.cgi?id=2070417

https://bugzilla.redhat.com/show_bug.cgi?id=2071070

https://bugzilla.redhat.com/show_bug.cgi?id=2072049

https://bugzilla.redhat.com/show_bug.cgi?id=2072377

https://bugzilla.redhat.com/show_bug.cgi?id=2072932

https://bugzilla.redhat.com/show_bug.cgi?id=2073012

https://bugzilla.redhat.com/show_bug.cgi?id=2075424

https://bugzilla.redhat.com/show_bug.cgi?id=2079582

https://bugzilla.redhat.com/show_bug.cgi?id=2083884

https://bugzilla.redhat.com/show_bug.cgi?id=2084566

https://bugzilla.redhat.com/show_bug.cgi?id=2089433

https://bugzilla.redhat.com/show_bug.cgi?id=2089623

https://bugzilla.redhat.com/show_bug.cgi?id=2091597

https://bugzilla.redhat.com/show_bug.cgi?id=2092756

https://bugzilla.redhat.com/show_bug.cgi?id=2095758

https://bugzilla.redhat.com/show_bug.cgi?id=2097209

https://bugzilla.redhat.com/show_bug.cgi?id=2097652

https://bugzilla.redhat.com/show_bug.cgi?id=2097947

https://bugzilla.redhat.com/show_bug.cgi?id=2100508

https://bugzilla.redhat.com/show_bug.cgi?id=2100862

https://bugzilla.redhat.com/show_bug.cgi?id=2101575

https://bugzilla.redhat.com/show_bug.cgi?id=2101787

https://bugzilla.redhat.com/show_bug.cgi?id=2107954

https://bugzilla.redhat.com/show_bug.cgi?id=2110203

https://bugzilla.redhat.com/show_bug.cgi?id=2111433

https://bugzilla.redhat.com/show_bug.cgi?id=2112296

https://bugzilla.redhat.com/show_bug.cgi?id=2120279

https://bugzilla.redhat.com/show_bug.cgi?id=2127109

Plugin Details

Severity: Medium

ID: 184779

File Name: rocky_linux_RLSA-2022-7472.nasl

Version: 1.0

Type: local

Published: 11/6/2023

Updated: 11/6/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.0

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2021-3507

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:rocky:linux:hivex, p-cpe:/a:rocky:linux:hivex-debuginfo, p-cpe:/a:rocky:linux:hivex-debugsource, p-cpe:/a:rocky:linux:hivex-devel, p-cpe:/a:rocky:linux:libguestfs, p-cpe:/a:rocky:linux:libguestfs-appliance, p-cpe:/a:rocky:linux:libguestfs-bash-completion, p-cpe:/a:rocky:linux:libguestfs-debuginfo, p-cpe:/a:rocky:linux:libguestfs-debugsource, p-cpe:/a:rocky:linux:libguestfs-devel, p-cpe:/a:rocky:linux:libguestfs-gfs2, p-cpe:/a:rocky:linux:libguestfs-gobject, p-cpe:/a:rocky:linux:libguestfs-gobject-debuginfo, p-cpe:/a:rocky:linux:libguestfs-gobject-devel, p-cpe:/a:rocky:linux:libguestfs-inspect-icons, p-cpe:/a:rocky:linux:libguestfs-java, p-cpe:/a:rocky:linux:libguestfs-java-debuginfo, p-cpe:/a:rocky:linux:libguestfs-java-devel, p-cpe:/a:rocky:linux:libguestfs-javadoc, p-cpe:/a:rocky:linux:libguestfs-man-pages-ja, p-cpe:/a:rocky:linux:libguestfs-man-pages-uk, p-cpe:/a:rocky:linux:libguestfs-rescue, p-cpe:/a:rocky:linux:libguestfs-rsync, p-cpe:/a:rocky:linux:libguestfs-tools, p-cpe:/a:rocky:linux:libguestfs-tools-c, p-cpe:/a:rocky:linux:libguestfs-tools-c-debuginfo, p-cpe:/a:rocky:linux:libguestfs-winsupport, p-cpe:/a:rocky:linux:libguestfs-xfs, p-cpe:/a:rocky:linux:libiscsi, p-cpe:/a:rocky:linux:libiscsi-debuginfo, p-cpe:/a:rocky:linux:libiscsi-debugsource, p-cpe:/a:rocky:linux:libiscsi-devel, p-cpe:/a:rocky:linux:libiscsi-utils, p-cpe:/a:rocky:linux:libiscsi-utils-debuginfo, p-cpe:/a:rocky:linux:libnbd, p-cpe:/a:rocky:linux:libnbd-bash-completion, p-cpe:/a:rocky:linux:libnbd-debuginfo, p-cpe:/a:rocky:linux:libnbd-debugsource, p-cpe:/a:rocky:linux:libnbd-devel, p-cpe:/a:rocky:linux:libtpms, p-cpe:/a:rocky:linux:libtpms-debuginfo, p-cpe:/a:rocky:linux:libtpms-debugsource, p-cpe:/a:rocky:linux:libtpms-devel, p-cpe:/a:rocky:linux:libvirt, p-cpe:/a:rocky:linux:libvirt-client, p-cpe:/a:rocky:linux:libvirt-client-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon, p-cpe:/a:rocky:linux:libvirt-daemon-config-network, p-cpe:/a:rocky:linux:libvirt-daemon-config-nwfilter, p-cpe:/a:rocky:linux:libvirt-daemon-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-interface, p-cpe:/a:rocky:linux:libvirt-daemon-driver-interface-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-network, p-cpe:/a:rocky:linux:libvirt-daemon-driver-network-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-nodedev, p-cpe:/a:rocky:linux:libvirt-daemon-driver-nodedev-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-nwfilter, p-cpe:/a:rocky:linux:libvirt-daemon-driver-nwfilter-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-qemu, p-cpe:/a:rocky:linux:libvirt-daemon-driver-qemu-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-secret, p-cpe:/a:rocky:linux:libvirt-daemon-driver-secret-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-core, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-core-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-disk, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-disk-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-gluster, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-gluster-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-iscsi, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-iscsi-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-iscsi-direct, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-iscsi-direct-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-logical, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-logical-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-mpath, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-mpath-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-rbd, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-rbd-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-scsi, p-cpe:/a:rocky:linux:libvirt-daemon-driver-storage-scsi-debuginfo, p-cpe:/a:rocky:linux:libvirt-daemon-kvm, p-cpe:/a:rocky:linux:libvirt-dbus, p-cpe:/a:rocky:linux:libvirt-dbus-debuginfo, p-cpe:/a:rocky:linux:libvirt-dbus-debugsource, p-cpe:/a:rocky:linux:libvirt-debuginfo, p-cpe:/a:rocky:linux:libvirt-debugsource, p-cpe:/a:rocky:linux:libvirt-devel, p-cpe:/a:rocky:linux:libvirt-docs, p-cpe:/a:rocky:linux:libvirt-libs, p-cpe:/a:rocky:linux:libvirt-libs-debuginfo, p-cpe:/a:rocky:linux:libvirt-lock-sanlock, p-cpe:/a:rocky:linux:libvirt-lock-sanlock-debuginfo, p-cpe:/a:rocky:linux:libvirt-nss, p-cpe:/a:rocky:linux:libvirt-nss-debuginfo, p-cpe:/a:rocky:linux:libvirt-python-debugsource, p-cpe:/a:rocky:linux:libvirt-wireshark, p-cpe:/a:rocky:linux:libvirt-wireshark-debuginfo, p-cpe:/a:rocky:linux:lua-guestfs, p-cpe:/a:rocky:linux:lua-guestfs-debuginfo, p-cpe:/a:rocky:linux:nbdfuse, p-cpe:/a:rocky:linux:nbdfuse-debuginfo, p-cpe:/a:rocky:linux:nbdkit, p-cpe:/a:rocky:linux:nbdkit-bash-completion, p-cpe:/a:rocky:linux:nbdkit-basic-filters, p-cpe:/a:rocky:linux:nbdkit-basic-filters-debuginfo, p-cpe:/a:rocky:linux:nbdkit-basic-plugins, p-cpe:/a:rocky:linux:nbdkit-basic-plugins-debuginfo, p-cpe:/a:rocky:linux:nbdkit-curl-plugin, p-cpe:/a:rocky:linux:nbdkit-curl-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-debuginfo, p-cpe:/a:rocky:linux:nbdkit-debugsource, p-cpe:/a:rocky:linux:nbdkit-devel, p-cpe:/a:rocky:linux:nbdkit-example-plugins, p-cpe:/a:rocky:linux:nbdkit-example-plugins-debuginfo, p-cpe:/a:rocky:linux:nbdkit-gzip-filter, p-cpe:/a:rocky:linux:nbdkit-gzip-filter-debuginfo, p-cpe:/a:rocky:linux:nbdkit-gzip-plugin, p-cpe:/a:rocky:linux:nbdkit-gzip-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-linuxdisk-plugin, p-cpe:/a:rocky:linux:nbdkit-linuxdisk-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-nbd-plugin, p-cpe:/a:rocky:linux:nbdkit-nbd-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-python-plugin, p-cpe:/a:rocky:linux:nbdkit-python-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-server, p-cpe:/a:rocky:linux:nbdkit-server-debuginfo, p-cpe:/a:rocky:linux:nbdkit-ssh-plugin, p-cpe:/a:rocky:linux:nbdkit-ssh-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-tar-filter, p-cpe:/a:rocky:linux:nbdkit-tar-filter-debuginfo, p-cpe:/a:rocky:linux:nbdkit-tar-plugin, p-cpe:/a:rocky:linux:nbdkit-tar-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-tmpdisk-plugin, p-cpe:/a:rocky:linux:nbdkit-tmpdisk-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-vddk-plugin, p-cpe:/a:rocky:linux:nbdkit-vddk-plugin-debuginfo, p-cpe:/a:rocky:linux:nbdkit-xz-filter, p-cpe:/a:rocky:linux:nbdkit-xz-filter-debuginfo, p-cpe:/a:rocky:linux:netcf, p-cpe:/a:rocky:linux:netcf-debuginfo, p-cpe:/a:rocky:linux:netcf-debugsource, p-cpe:/a:rocky:linux:netcf-devel, p-cpe:/a:rocky:linux:netcf-libs, p-cpe:/a:rocky:linux:netcf-libs-debuginfo, p-cpe:/a:rocky:linux:ocaml-hivex, p-cpe:/a:rocky:linux:ocaml-hivex-debuginfo, p-cpe:/a:rocky:linux:ocaml-hivex-devel, p-cpe:/a:rocky:linux:ocaml-libguestfs, p-cpe:/a:rocky:linux:ocaml-libguestfs-debuginfo, p-cpe:/a:rocky:linux:ocaml-libguestfs-devel, p-cpe:/a:rocky:linux:ocaml-libnbd, p-cpe:/a:rocky:linux:ocaml-libnbd-debuginfo, p-cpe:/a:rocky:linux:ocaml-libnbd-devel, p-cpe:/a:rocky:linux:perl-sys-guestfs, p-cpe:/a:rocky:linux:perl-sys-guestfs-debuginfo, p-cpe:/a:rocky:linux:perl-sys-virt, p-cpe:/a:rocky:linux:perl-sys-virt-debuginfo, p-cpe:/a:rocky:linux:perl-sys-virt-debugsource, p-cpe:/a:rocky:linux:perl-hivex, p-cpe:/a:rocky:linux:perl-hivex-debuginfo, p-cpe:/a:rocky:linux:python3-hivex, p-cpe:/a:rocky:linux:python3-hivex-debuginfo, p-cpe:/a:rocky:linux:python3-libguestfs, p-cpe:/a:rocky:linux:python3-libguestfs-debuginfo, p-cpe:/a:rocky:linux:python3-libnbd, p-cpe:/a:rocky:linux:python3-libnbd-debuginfo, p-cpe:/a:rocky:linux:python3-libvirt, p-cpe:/a:rocky:linux:python3-libvirt-debuginfo, p-cpe:/a:rocky:linux:qemu-guest-agent, p-cpe:/a:rocky:linux:qemu-guest-agent-debuginfo, p-cpe:/a:rocky:linux:qemu-img, p-cpe:/a:rocky:linux:qemu-img-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm, p-cpe:/a:rocky:linux:qemu-kvm-block-curl, p-cpe:/a:rocky:linux:qemu-kvm-block-curl-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-block-gluster, p-cpe:/a:rocky:linux:qemu-kvm-block-gluster-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-block-iscsi, p-cpe:/a:rocky:linux:qemu-kvm-block-iscsi-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-block-rbd, p-cpe:/a:rocky:linux:qemu-kvm-block-rbd-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-block-ssh, p-cpe:/a:rocky:linux:qemu-kvm-block-ssh-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-common, p-cpe:/a:rocky:linux:qemu-kvm-common-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-core, p-cpe:/a:rocky:linux:qemu-kvm-core-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-debugsource, p-cpe:/a:rocky:linux:qemu-kvm-docs, p-cpe:/a:rocky:linux:qemu-kvm-hw-usbredir, p-cpe:/a:rocky:linux:qemu-kvm-hw-usbredir-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-tests, p-cpe:/a:rocky:linux:qemu-kvm-ui-opengl, p-cpe:/a:rocky:linux:qemu-kvm-ui-opengl-debuginfo, p-cpe:/a:rocky:linux:qemu-kvm-ui-spice, p-cpe:/a:rocky:linux:qemu-kvm-ui-spice-debuginfo, p-cpe:/a:rocky:linux:ruby-hivex, p-cpe:/a:rocky:linux:ruby-hivex-debuginfo, p-cpe:/a:rocky:linux:ruby-libguestfs, p-cpe:/a:rocky:linux:ruby-libguestfs-debuginfo, p-cpe:/a:rocky:linux:seabios, p-cpe:/a:rocky:linux:seabios-bin, p-cpe:/a:rocky:linux:seavgabios-bin, p-cpe:/a:rocky:linux:sgabios, p-cpe:/a:rocky:linux:sgabios-bin, p-cpe:/a:rocky:linux:supermin, p-cpe:/a:rocky:linux:supermin-debuginfo, p-cpe:/a:rocky:linux:supermin-debugsource, p-cpe:/a:rocky:linux:supermin-devel, p-cpe:/a:rocky:linux:swtpm, p-cpe:/a:rocky:linux:swtpm-debuginfo, p-cpe:/a:rocky:linux:swtpm-debugsource, p-cpe:/a:rocky:linux:swtpm-devel, p-cpe:/a:rocky:linux:swtpm-libs, p-cpe:/a:rocky:linux:swtpm-libs-debuginfo, p-cpe:/a:rocky:linux:swtpm-tools, p-cpe:/a:rocky:linux:swtpm-tools-debuginfo, p-cpe:/a:rocky:linux:swtpm-tools-pkcs11, p-cpe:/a:rocky:linux:virt-dib, p-cpe:/a:rocky:linux:virt-dib-debuginfo, p-cpe:/a:rocky:linux:virt-v2v, p-cpe:/a:rocky:linux:virt-v2v-bash-completion, p-cpe:/a:rocky:linux:virt-v2v-debuginfo, p-cpe:/a:rocky:linux:virt-v2v-debugsource, p-cpe:/a:rocky:linux:virt-v2v-man-pages-ja, p-cpe:/a:rocky:linux:virt-v2v-man-pages-uk, cpe:/o:rocky:linux:8

Required KB Items: Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/8/2022

Vulnerability Publication Date: 5/6/2021

Reference Information

CVE: CVE-2021-3507, CVE-2022-0897, CVE-2022-2211, CVE-2022-23645