Comment 166 for bug 2059809

Revision history for this message
Thomas Goirand (thomas-goirand) wrote : Re: Arbitrary file access through QCOW2 external data file (CVE-2024-32498)

Dan, can you write backports of your Additional_qemu_safety_checking_on_base_images.patch then? I've seen that the function _test_create_image in test_utils.py, in previous versions, has less mock patches, and doesn't even exist in Victoria. If you could backport it as far as possible, that'd be great.

As for Felix's patch, I'm worried about the fact there's many qemu-img info calls everywhere in Cinder, as mentioned earlier in this thread.

Last, can I make a 2nd call for postponing the disclosure? We still don't have definitive patches (or just got them), and it's taking me a lot of time to backport to 4 or 5 more OpenStack releases. Yet alone doing functional testing to check the regressions. I consider one week of backport + tests to be an ok-ish deadline when we have definitive patch-sets, but that's not what's going on with this issue.