USN-5835-2: OpenStack Glance vulnerability
31 January 2023
OpenStack Glance could be made to expose sensitive information.
Releases
Packages
- glance - OpenStack Image Registry and Delivery Service
Details
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that OpenStack Glance incorrectly handled VMDK image processing.
An authenticated attacker could possibly supply a specially crafted VMDK
flat image and obtain arbitrary files from the server containing sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5835-1: cinder-volume, python3-cinder, cinder-backup, cinder, cinder-api, cinder-common, cinder-scheduler
- USN-5835-3: nova-compute-ironic, nova-common, nova-spiceproxy, nova-volume, nova-api-os-volume, nova, nova-api-os-compute, nova-compute-libvirt, nova-compute-vmware, nova-api, nova-ajax-console-proxy, nova-novncproxy, nova-compute, nova-doc, nova-cells, nova-compute-lxc, nova-scheduler, nova-compute-qemu, nova-compute-kvm, nova-compute-xen, nova-api-metadata, nova-conductor, python3-nova, nova-serialproxy
- USN-5835-4: cinder-volume, python3-cinder, python-cinder, cinder-backup, cinder, cinder-api, cinder-common, cinder-scheduler
- USN-5835-5: python-nova, nova-common, nova-spiceproxy, nova-volume, nova-xvpvncproxy, nova-api-os-volume, nova-placement-api, nova, nova-network, nova-api-os-compute, nova-consoleauth, nova-compute-libvirt, nova-compute-vmware, nova-api, nova-ajax-console-proxy, nova-novncproxy, nova-compute, nova-doc, nova-cells, nova-compute-lxc, nova-scheduler, nova-compute-qemu, nova-compute-kvm, nova-compute-xen, nova-console, nova-api-metadata, nova-conductor, nova-serialproxy
- USN-6882-2: cinder-volume, python3-cinder, cinder-backup, cinder, cinder-api, cinder-common, cinder-scheduler