Virtuozzo OnApp 6.0 CloudBoot Security Update
To mitigate the vulnerabilities on KVM CloudBoot compute resources we recommend updating the following packages:
- CentOS 6
- kernel 2.6.32-754.12.2.el6.x86_64
- libvirt 0.10.2-64.el6_10.1
- qemu-kvm 0.12.1.2-2.506.el6_10.3
- CentOS 7
- kernel 3.10.0-957.12.2.el7.x86_64
- libvirt 4.5.0-10.el7_6.7
- qemu-kvm 2.12.0-18.el7_6.5.1
Use CloudBoot Compute Resources and CloudBoot Backup Server upgrade procedures to install the update. ‘Simple reboot’ and ‘Migrate and Reboot’ options are available.
| Key | Type | Release Notes | Affects Version/s |
|---|---|---|---|
| CLOUDBOOT-421 | Improvement | Updated the following components for CentOS 7 Xen compute resources:
| |
| CLOUDBOOT-425 | Improvement | Updated the following components for CentOS 6 Xen compute resources:
| |
| CLOUDBOOT-429 | Improvement | Updated an onapp-messaging version to 6.0.0-3 for all CloudBoot compute resources. | |
| CLOUDBOOT-428 | Fix | The STORAGENODE guests on Xen were not reported via SNMP because storage controllers were managed with XM/XL while other guests were managed with Libvirt. | 6.0 |
| CLOUDBOOT-435 | Fix | Fixed the issue with data storage utilization when incorrect zombie_disks_size value was displayed in the database. | 5.5.0-92-6.0.0-159 |
| CLOUDBOOT-436 | Fix | Updated qemu-kvm-ev version to 2.12.0-18.el7_6.5.1 for CentOS 7 KVM ramdisk to address the CVE-2018-12130, CVE-2018-12126, CVE-2018-12127, and the CVE-2019-11091 issue. | 5.5.0-92-6.0.0-159 |
| CLOUDBOOT-440 | Fix | Updated the following components for CentOS 7 KVM compute resources to address the CVE-2018-12130, CVE-2018-12126, CVE-2018-12127, and the CVE-2019-11091 issue:
| 5.5.0-92-6.0.0-159 |
| CLOUDBOOT-441 | Fix | Updated the following components for CentOS 6 KVM ramdisk to address the CVE-2018-12130, CVE-2018-12126, CVE-2018-12127, and the CVE-2019-11091 issue:
| 5.0-6.0.0-122 |
| CLOUDBOOT-444 | Fix | Updated kernel version to 3.10.0-957.12.2.el7.x86_64 for CentOS 7 default ramdisk to address the CVE-2018-12130, CVE-2018-12126, CVE-2018-12127, and the CVE-2019-11091 issue. | 5.5.0-92-6.0.0-159 |