USN-5835-1: Cinder vulnerability
31 January 2023
Cinder could be made to expose sensitive information.
Releases
Packages
- cinder - OpenStack storage service
Details
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Cinder incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
Ubuntu 20.04
After a standard system update you need to restart Cinder to make all the
necessary changes.
References
Related notices
- USN-5835-2: glance-common, python-glance-doc, glance-api, glance, python3-glance
- USN-5835-3: nova-compute-kvm, nova-api-metadata, nova-api, nova-compute-ironic, nova-compute-libvirt, nova-compute-qemu, nova-compute-lxc, nova-api-os-compute, nova-novncproxy, nova-compute, nova, nova-doc, nova-serialproxy, nova-compute-vmware, nova-compute-xen, nova-scheduler, nova-conductor, nova-api-os-volume, nova-volume, nova-ajax-console-proxy, nova-spiceproxy, nova-cells, nova-common, python3-nova
- USN-5835-4: cinder-scheduler, cinder-volume, cinder-api, cinder-common, python-cinder, cinder, cinder-backup, python3-cinder
- USN-5835-5: nova-compute-kvm, python-nova, nova-api-metadata, nova-api, nova-compute-libvirt, nova-compute-qemu, nova-console, nova-compute-lxc, nova-api-os-compute, nova-novncproxy, nova-compute, nova, nova-doc, nova-serialproxy, nova-compute-vmware, nova-compute-xen, nova-scheduler, nova-conductor, nova-api-os-volume, nova-volume, nova-consoleauth, nova-ajax-console-proxy, nova-placement-api, nova-spiceproxy, nova-xvpvncproxy, nova-network, nova-cells, nova-common
- USN-6882-2: cinder-scheduler, cinder-volume, cinder-api, cinder-common, cinder, cinder-backup, python3-cinder