Comment 242 for bug 2059809

Revision history for this message
Arnaud Morin (arnaud-morin) wrote : Re: Arbitrary file access through QCOW2 external data file (CVE-2024-32498)

it's reading an external file (I used /etc/nova/nova.conf) in my sample.

The file is actually not readable by the qemu user (libvirt-qemu on my system) so nova is printing a stack trace in logs:

Could not open '/etc/nova/nova.conf': Permission denied