USN-5835-5: Nova vulnerability
9 February 2023
Nova could be made to expose sensitive information.
Releases
Packages
- nova - OpenStack Compute cloud infrastructure
Details
USN-5835-3 fixed vulnerabilities in Nova. This update provides the
corresponding updates for Ubuntu 18.04 LTS.
Original advisory details:
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Nova incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5835-1: cinder-scheduler, cinder-volume, cinder-common, cinder, python3-cinder, cinder-backup, cinder-api
- USN-5835-2: glance-common, glance, python-glance-doc, glance-api, python3-glance
- USN-5835-3: nova-common, nova-compute, nova-compute-vmware, nova-api, python3-nova, nova-compute-lxc, nova-serialproxy, nova-api-os-volume, nova-api-metadata, nova-compute-kvm, nova-cells, nova-doc, nova-scheduler, nova-conductor, nova-spiceproxy, nova-compute-ironic, nova-compute-qemu, nova-ajax-console-proxy, nova-api-os-compute, nova-volume, nova, nova-compute-libvirt, nova-compute-xen, nova-novncproxy
- USN-5835-4: cinder-scheduler, cinder-volume, cinder-common, python-cinder, cinder, python3-cinder, cinder-backup, cinder-api
- USN-6882-2: cinder-scheduler, cinder-volume, cinder-common, cinder, python3-cinder, cinder-backup, cinder-api