USN-5835-3: Nova vulnerability
31 January 2023
Nova could be made to expose sensitive information.
Releases
Packages
- nova - OpenStack Compute cloud infrastructure
Details
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Nova incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5835-1: cinder-api, cinder-scheduler, cinder-volume, cinder-common, cinder-backup, python3-cinder, cinder
- USN-5835-2: python-glance-doc, glance-common, glance-api, python3-glance, glance
- USN-5835-4: cinder-api, python-cinder, cinder-scheduler, cinder-volume, cinder-common, cinder-backup, python3-cinder, cinder
- USN-5835-5: nova-api-os-compute, nova-novncproxy, nova-cells, nova-doc, python-nova, nova, nova-compute-lxc, nova-common, nova-compute-kvm, nova-placement-api, nova-api-metadata, nova-xvpvncproxy, nova-conductor, nova-compute-libvirt, nova-compute-qemu, nova-volume, nova-scheduler, nova-consoleauth, nova-api-os-volume, nova-api, nova-serialproxy, nova-console, nova-network, nova-compute, nova-ajax-console-proxy, nova-spiceproxy, nova-compute-xen, nova-compute-vmware
- USN-6882-2: cinder-api, cinder-scheduler, cinder-volume, cinder-common, cinder-backup, python3-cinder, cinder