Openstack Security Advisory: OSSA-2023-002: Arbitrary file access through custom VMDK flat descriptor

Bug #2006135 reported by Michel Thebeau [WIND]
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Thales Elero Cervi

Bug Description

Brief Description
-----------------
There is a new Openstack Security Advisory: https://security.openstack.org/ossa/OSSA-2023-002.html for Glance, Nova and Cinder. The advisory lists patches for Glance and Cinder back to Train, and patches for Nova back to Xena.

It is not confirmed that Starlingx is impacted.

Severity
--------
Medium: Security Issue

Steps to Reproduce
------------------
N/A

Expected Behavior
------------------
N/A

Actual Behavior
----------------
N/A

Reproducibility
---------------
Reproducible

System Configuration
--------------------
N/A

Branch/Pull Time/Commit
-----------------------
stx main branch

Last Pass
---------
N/A

Timestamp/Logs
--------------
N/A

Test Activity
-------------
Security vulnerabilities review

Workaround
----------
None

Revision history for this message
Ghada Khalil (gkhalil) wrote :

Assigning to Thales for review by the stx-openstack team

tags: added: stx.distro.openstack stx.security
information type: Private Security → Public Security
Changed in starlingx:
assignee: nobody → Thales Elero Cervi (tcervi)
Revision history for this message
Thales Elero Cervi (tcervi) wrote :

Next StarlingX relese (stx.9.0) will deliver an stx-opesntack application with OpenStack Antelope based images generated on top of the `stable/2023.1` branch and all affected services have a fix for this on this branch:

* Cinder: https://opendev.org/openstack/cinder/commit/1186f5d9f4ef7a0aa8bf6d865c1f42843fe91eaa
Code can be found on `stable/2023.1` branch: https://opendev.org/openstack/cinder/src/branch/stable/2023.1/cinder/image/image_utils.py#L83

* Glance: https://opendev.org/openstack/glance/commit/907c56265438da43c13bf1a3369d5459b1267e34
Code can be found on `stable/2023.1` branch: https://opendev.org/openstack/glance/src/branch/stable/2023.1/glance/async_/flows/plugins/image_conversion.py#L120

* Nova: https://opendev.org/openstack/nova/commit/e90e58e7f918baa3b461353f333f837eafbd8411
Code can be found on `stable/2023.1` branch: https://opendev.org/openstack/nova/src/branch/stable/2023.1/nova/conf/compute.py#L1019

tags: added: stx.9.0
Revision history for this message
Thales Elero Cervi (tcervi) wrote :
Changed in starlingx:
status: New → Fix Released
Ghada Khalil (gkhalil)
Changed in starlingx:
importance: Undecided → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.