Comment 79 for bug 1996188

Revision history for this message
Guillaume Espanel (guillaume-espanel) wrote : Re: Arbitrary file access through custom VMDK flat descriptor (CVE-2022-47951)

Hi! I agree, lets get this out sooner than later :)

- Glance and its backports LGTM, but do I understand correctly we will not patch async_.flows.convert._Convert.execute() because it's an admin-only call?
- Cinder is a bit heavier but LGTM too.
- Nova still looks good :)