USN-5835-4: Cinder vulnerability
9 February 2023
Cinder could be made to expose sensitive information.
Releases
Packages
- cinder - OpenStack storage service
Details
USN-5835-1 fixed vulnerabilities in Cinder. This update provides the
corresponding updates for Ubuntu 18.04 LTS. In addition, a regression was
fixed for Ubuntu 20.04 LTS.
Original advisory details:
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Cinder incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
After a standard system update you need to restart Cinder to make all the
References
Related notices
- USN-5835-1: cinder-common, python3-cinder, cinder-volume, cinder-backup, cinder, cinder-scheduler, cinder-api
- USN-5835-2: glance, glance-common, python3-glance, glance-api, python-glance-doc
- USN-5835-3: python3-nova, nova-api-os-compute, nova-compute-ironic, nova-volume, nova-doc, nova-serialproxy, nova-api-metadata, nova-ajax-console-proxy, nova-conductor, nova-compute-libvirt, nova-compute-lxc, nova-compute-xen, nova-cells, nova-spiceproxy, nova-compute, nova-api, nova, nova-compute-kvm, nova-novncproxy, nova-api-os-volume, nova-compute-qemu, nova-compute-vmware, nova-common, nova-scheduler
- USN-5835-5: nova-placement-api, nova-api-os-compute, nova-volume, nova-doc, nova-consoleauth, nova-serialproxy, nova-api-metadata, nova-ajax-console-proxy, nova-conductor, nova-compute-libvirt, nova-compute-lxc, nova-compute-xen, nova-network, nova-console, nova-cells, nova-spiceproxy, nova-compute, nova-api, nova, nova-compute-kvm, nova-novncproxy, python-nova, nova-xvpvncproxy, nova-api-os-volume, nova-compute-qemu, nova-compute-vmware, nova-common, nova-scheduler
- USN-6882-2: cinder-common, python3-cinder, cinder-volume, cinder-backup, cinder, cinder-scheduler, cinder-api