RHSA-2024:5113HighCVSS 5.5
Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-40767 — openstack-nova: Regression VMDK/qcow arbitrary file access
🎯 Affected products14
- Red Hat OpenStack Platform 16.1
- openstack-nova-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-1:20.4.1-1.20221005193235.el8ost.src as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-api-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-common-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-compute-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-conductor-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-console-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-migration-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-novncproxy-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-scheduler-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-serialproxy-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- openstack-nova-spicehtml5proxy-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
- python3-nova-1:20.4.1-1.20221005193235.el8ost.noarch as a component of Red Hat OpenStack Platform 16.1
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258