Comment 223 for bug 2059809

Revision history for this message
Brian Rosmaita (brian-rosmaita) wrote : Re: Arbitrary file access through QCOW2 external data file (CVE-2024-32498)

Attaching a "unified" patch containing Felix and Dan's changes. Difference from the previous patch is that it allows a qcow2 to have a backing file (this is needed for the generic nfs driver); qcow2's with backing files, however, continue to be unconditionally rejected when downloaded from Glance to create a volume.