Comment 250 for bug 2059809

Revision history for this message
Kurt Garloff (kgarloff) wrote : Re: Arbitrary file access through QCOW2 external data file (CVE-2024-32498)

Testing some of the exploit scenarios, I could no longer trigger the issue. Testing however was done without the latest patch from this morning from @arnaud-morin and I did not dig myself into it deeply enough to come up with own ideas for corner cases. Thanks @arnaud-morin, @felix.huettner for having done so.

Question to @fungi:
* Is the number of the OSSA known, can we have a link to the upcoming advisory?
* Due to the late patches, we are now fighting for every minute -- if this becomes public half an hour later, this would be helpful to have everything prepared ...