RHSA-2024:5083HighCVSS 5.5

Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.3 security update

Published
August 7, 2024
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-40767 — openstack-nova: Regression VMDK/qcow arbitrary file access

🎯 Affected products13

  • Red Hat OpenStack Platform 17.1
  • openstack-nova-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-1:23.2.3-17.1.20231018130829.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-api-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-common-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-compute-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-conductor-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-migration-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-novncproxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-scheduler-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-serialproxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-nova-spicehtml5proxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • python3-nova-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (4)