Comment 175 for bug 2059809

Revision history for this message
Dr. Jens Harbott (j-harbott) wrote (last edit ): Re: Arbitrary file access through QCOW2 external data file (CVE-2024-32498)

O.k., maybe I'm misunderstanding something about the intention of the glance patch. I was expecting it to stop the exploit workflow at the "openstack image create" stage by not allowing the uploaded image to become active, but actually the creation succeeds without error afaict. All four patches from #136 applied. I also don't think image conversion is involved here, just a direct upload of a qcow2 image, right? Simple devstack deployment from master without any changes to local.conf.