-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2023.2332
             Security update for kubevirt, virt-api-container,
virt-controller-container, virt-handler-container, virt-launcher-container,
         virt-libguestfs-tools-container, virt-operator-container
                               26 April 2023

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           kubevirt
                   virt-api-container
                   virt-controller-container
                   virt-handler-container
                   virt-launcher-container
                   virt-libguestfs-tools-container
                   virt-operator-container
Publisher:         SUSE
Operating System:  SUSE
Resolution:        Patch/Upgrade
CVE Names:         CVE-2023-26484  

Original Bulletin: 
   https://www.suse.com/support/update/announcement/2023/suse-su-20231967-1

Comment: CVSS (Max):  8.0 CVE-2023-26484 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
         CVSS Source: SUSE
         Calculator:  https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

- --------------------------BEGIN INCLUDED TEXT--------------------

Security update for kubevirt, virt-api-container, virt-controller-container,
virt-handler-container, virt-launcher-container,
virt-libguestfs-tools-container, virt-operator-container

Announcement ID:  SUSE-SU-2023:1967-1
     Rating:      important
                    o #1208916
   References:      o #1209359

Cross-References:   o CVE-2023-26484

                    o CVE-2023-26484 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N
                      /S:C/C:H/I:H/A:H
  CVSS scores:      o CVE-2023-26484 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/
                      S:C/C:H/I:H/A:N

                    o Containers Module 15-SP4
                    o openSUSE Leap 15.4
                    o openSUSE Leap Micro 5.3
                    o SUSE Linux Enterprise High Performance Computing 15 SP4
                    o SUSE Linux Enterprise Micro 5.3
                    o SUSE Linux Enterprise Micro 5.4
    Affected        o SUSE Linux Enterprise Micro for Rancher 5.3
    Products:       o SUSE Linux Enterprise Micro for Rancher 5.4
                    o SUSE Linux Enterprise Real Time 15 SP4
                    o SUSE Linux Enterprise Server 15 SP4
                    o SUSE Linux Enterprise Server for SAP Applications 15 SP4
                    o SUSE Manager Proxy 4.3
                    o SUSE Manager Retail Branch Server 4.3
                    o SUSE Manager Server 4.3

An update that solves one vulnerability and has one fix can now be installed.

Description:

This update for kubevirt, virt-api-container, virt-controller-container,
virt-handler-container, virt-launcher-container,
virt-libguestfs-tools-container, virt-operator-container fixes the following
issues:

  o CVE-2023-26484: Limit operator secrets permission. (bsc#1209359)

kubevirt is also rebuilt with a supported GO compiler (bsc#1208916)

Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  o openSUSE Leap Micro 5.3
    zypper in -t patch openSUSE-Leap-Micro-5.3-2023-1967=1
  o openSUSE Leap 15.4
    zypper in -t patch openSUSE-SLE-15.4-2023-1967=1
  o SUSE Linux Enterprise Micro for Rancher 5.3
    zypper in -t patch SUSE-SLE-Micro-5.3-2023-1967=1
  o SUSE Linux Enterprise Micro 5.3
    zypper in -t patch SUSE-SLE-Micro-5.3-2023-1967=1
  o SUSE Linux Enterprise Micro for Rancher 5.4
    zypper in -t patch SUSE-SLE-Micro-5.4-2023-1967=1
  o SUSE Linux Enterprise Micro 5.4
    zypper in -t patch SUSE-SLE-Micro-5.4-2023-1967=1
  o Containers Module 15-SP4
    zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2023-1967=1

Package List:

  o openSUSE Leap Micro 5.3 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
  o openSUSE Leap 15.4 (x86_64)
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
       kubevirt-virt-api-0.54.0-150400.3.13.1
       kubevirt-virt-api-debuginfo-0.54.0-150400.3.13.1
       kubevirt-virt-controller-0.54.0-150400.3.13.1
       obs-service-kubevirt_containers_meta-0.54.0-150400.3.13.1
       kubevirt-virt-operator-0.54.0-150400.3.13.1
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-tests-debuginfo-0.54.0-150400.3.13.1
       kubevirt-container-disk-debuginfo-0.54.0-150400.3.13.1
       kubevirt-virt-handler-0.54.0-150400.3.13.1
       kubevirt-virt-launcher-0.54.0-150400.3.13.1
       kubevirt-virt-controller-debuginfo-0.54.0-150400.3.13.1
       kubevirt-virt-launcher-debuginfo-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virt-handler-debuginfo-0.54.0-150400.3.13.1
       kubevirt-container-disk-0.54.0-150400.3.13.1
       kubevirt-virt-operator-debuginfo-0.54.0-150400.3.13.1
       kubevirt-tests-0.54.0-150400.3.13.1
  o SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
  o SUSE Linux Enterprise Micro 5.3 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
  o SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
  o SUSE Linux Enterprise Micro 5.4 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1
  o Containers Module 15-SP4 (x86_64)
       kubevirt-virtctl-0.54.0-150400.3.13.1
       kubevirt-manifests-0.54.0-150400.3.13.1
       kubevirt-virtctl-debuginfo-0.54.0-150400.3.13.1

References:

  o https://www.suse.com/security/cve/CVE-2023-26484.html
  o https://bugzilla.suse.com/show_bug.cgiid=1208916
  o https://bugzilla.suse.com/show_bug.cgiid=1209359

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: https://auscert.org.au/gpg-key/

iQIVAwUBZEiAuckNZI30y1K9AQjCHxAAiXmRTTbPukvkAWCPijegPDAJy5VojVVZ
CwebMeEyoNF8EhQovEjUdYoYH8veRK7RQpN7VwwVjp2+rl1+aXrhYF9utcgQz9Fy
xCQuL40Msy3HAmMGZlWxAyfVvs+i8Edy7th11ND8snvSr68qLEmJ7ShXUPgS365D
woxsimTyR5yO1hHZAGFpD2MxIMXwqJ4TP8HrLlDm2Ay0j+masHO+4LiFQGMv0SZw
Eg2gSocZNVgwufYe9Ys7S0vekwL6oVEE8J3e3mxUeTUZsao12bJmfoizJlpTrefe
mrYKnpmRiDneDSQgmgZUFTnSIxNXXmtDVRfenh+f15v9f45Y5Ipyp/XPibHwph3q
HEtakYzuEtKELXOwEUm/lHAP4u5Y+qm9st3lUL9XWOkh1ltr7/00QITyHiNpHToQ
3sIiMjecEJ7CSyddJv+qSMurKvMEMyk8Ic9iA+BjMjzCvNFvmNQ6xql5KnDdl09B
DVavcSgB97a4mJeyQRaNxvX91lUFUk8IUDj6AG+i59Vrr6Iq+D5jjxlvCeLxnbWN
O+vN2LRiUBZVdfKTr4KwpXIj++pb4IqCtwKtyYG0sVPJRKeOgs+m1YvH5HZenFfJ
Da3S8TWI3QWKjS0cAbiA8HdlKXeJhSz/4PeNl41Y0LwVAahTGpPpgNvD3HB+pqjV
5WnECaw17/E=
=qdk5
-----END PGP SIGNATURE-----