-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Critical: Multicluster Engine for Kubernetes 2.1.1 security update and bug fixes Advisory ID: RHSA-2022:6424-01 Product: multicluster engine for Kubernetes Advisory URL: https://access.redhat.com/errata/RHSA-2022:6424 Issue date: 2022-09-12 CVE Names: CVE-2022-36067 ===================================================================== 1. Summary: Multicluster Engine for Kubernetes 2.1.1 General Availability release images, which fix bugs and update container images. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Multicluster Engine for Kubernetes 2.1.1 images Multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy. Security updates: * vm2: Sandbox Escape in vm2 (CVE-2022-36067) Bug fixes: * MCE 2.1.1 images (BZ# 2125039) 3. Solution: For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html-single/multicluster_engine/index#installing-while-connected-online 4. Bugs fixed (https://bugzilla.redhat.com/): 2124794 - CVE-2022-36067 vm2: Sandbox Escape in vm2 2125039 - MCE 2.1.1 Images 5. References: https://access.redhat.com/security/cve/CVE-2022-36067 https://access.redhat.com/security/updates/classification/#critical 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYx/ZDNzjgjWX9erEAQiE1A/+N5NQLZPXT+DSyeUKNaNZFZfOOGgzG4ka Kbekz34kxM8SVjj7Io17wEyfkeakisKsEVXyv+MyYqAurMPFQBHfehzUpMM7XWUK frG7ARttABYNIQsXZXNuRV6B7rjB9jkB2pdq2OEbSa+3ubXfzXa++X0S5r1bDMb+ UYXAIlR9YpO5fYJ6xTjEg6v19ifP6aqAHwzeNYA+IRPGqeNoK1PvNPo4+VT2bce8 xKTDyC0vi6YWE/3RJ0OqEvJty2vSt5qESOMedmnZmd2VyUSzg2vuJvm+3DHJZ2tQ BKz2L0hHeVuph0lFVRdVBy3kIEZ45cm5lc27jSnwpoNBH0xCcJjUjYeTkgyqfYUv uIcLz/mrkdUX2fNzY844ifomc2z0rODLUS0jgZ3kzWp9gfoijoOBm9w5Mn6LFo+G JF6SGR6PKHCwXLwKdLCwXf4b7rP7goLm2+zvYzbTy/W0hkJ5jao+lEKOtIGNwnre Dk4yP5x1mKXwAqnnCJq9pmMsmYXghhMcY1ffTrUDiSCy12C8P5UN+afunsXrL3Z5 u17csp6j//VgC4qA+eROKncQBl39FQSMhtW5AfZCdgm6bUvjbIFWkTAIM41POgpT n2q+0cRCzpeGv3bwbrGUp9KtL2htJYyfNsQERnP6pDMWt+DjHuDePIX85xTZxJRl kAfMRwtCpEc= =zDFx -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce