Comment 49 for bug 2071734

Revision history for this message
sean mooney (sean-k-mooney) wrote : Re: Regression VMDK/qcow arbitrary file access (CVE-2024-40767)

for older disto release we have a number of optional follow up patches for unit tests sablity/fucntionality

for example https://review.opendev.org/c/openstack/nova/+/923878/3 and https://review.opendev.org/c/openstack/nova/+/923935/1

these just skip unit tests if the distro ships a qemu-img that does not support the relevant format ectra.

if you have any issues with the package build related to the ported unit tests then you should be able to apply those commits.

we have proposed those on top of the iso patches to all upstream stable releases since they are not directly related to this cve and are related to the content of the iso fix series, namely the imported unit tests from glance.

i have not had time to create patches for our downstream branches yet
which are nominally based on wallaby and train but I'm expecting the patches to apply cleanly to those as well if you have the iso format backports.

I'm not sure how useful patches for our downstream branches would be to attach here as we have some downstream-only feature backport but i can potentially share those after the discourser