RHSA-2024:5083HighCVSS 5.5
Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.3 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-40767 — openstack-nova: Regression VMDK/qcow arbitrary file access
🎯 Affected products13
- Red Hat OpenStack Platform 17.1
- openstack-nova-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-1:23.2.3-17.1.20231018130829.el9ost.src as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-api-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-common-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-compute-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-conductor-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-migration-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-novncproxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-scheduler-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-serialproxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- openstack-nova-spicehtml5proxy-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
- python3-nova-1:23.2.3-17.1.20231018130829.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258