UbuntuUpdates.org

Package "nova-api"

Name: nova-api

Description:

OpenStack Compute - API frontend

Latest version: 2:21.2.4-0ubuntu2.13
Release: focal (20.04)
Level: updates
Repository: main
Head package: nova
Homepage: https://launchpad.net/nova

Links


Download "nova-api"


Other versions of "nova-api" in Focal

Repository Area Version
base main 2:21.0.0~b3~git2020041013.57ff308d6d-0ubuntu2
security main 2:21.2.4-0ubuntu2.11
proposed main 2:21.2.4-0ubuntu2.14

Changelog

Version: 2:21.2.4-0ubuntu2.13 2024-08-22 17:07:12 UTC

  nova (2:21.2.4-0ubuntu2.13) focal; urgency=medium

  * d/p/lp2024258-database-Archive-parent-and-child-rows-trees-one-at-.patch:
    Fix package install/autopkgtests (IndentationError in test_archive.py:172)
    (LP: #2024258)

Source diff to previous version
2024258 Performance degradation archiving DB with large numbers of FK related records

Version: 2:21.2.4-0ubuntu2.11 2024-07-23 20:07:06 UTC

  nova (2:21.2.4-0ubuntu2.11) focal-security; urgency=medium

  * SECURITY UPDATE: Incomplete file access fix and regression for QCOW2
    backing files and VMDK flat descriptors
    - debian/patches/CVE-2024-40767-pre1.patch: port format inspector tests
      from glance.
    - debian/patches/CVE-2024-40767-pre2.patch: reproduce iso regression
      with deep format inspection.
    - debian/patches/CVE-2024-40767-pre3.patch: add iso file format
      inspector.
    - debian/patches/CVE-2024-40767-pre4.patch: fix qemu-img version
      dependent tests.
    - debian/patches/CVE-2024-40767-pre5.patch: stabilize iso format unit
      tests.
    - debian/patches/CVE-2024-40767.patch: change force_format strategy to
      catch mismatches.
    - CVE-2024-40767
  * Replace CVE-2024-32498 patches with final versions from git.
    - debian/patches/CVE-2024-32498-*
  * debian/control: added qemu-utils to Build-Depends so qemu-img is
    available for new tests.
  * Note: this package does _not_ contain the changes from
    2:21.2.4-0ubuntu2.9 and 2:21.2.4-0ubuntu2.10 in focal-proposed.

 -- Marc Deslauriers <email address hidden> Wed, 17 Jul 2024 14:01:19 -0400

Source diff to previous version
CVE-2024-32498 An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom

Version: 2:21.2.4-0ubuntu2.8 2024-07-08 16:07:09 UTC

  nova (2:21.2.4-0ubuntu2.8) focal-security; urgency=medium

  * SECURITY UPDATE: Arbitrary file access via custom QCOW2 external data
    (LP: #2059809)
    - debian/patches/CVE-2024-32498-pre1.patch: create qcow2 disks with the
      correct size without extending.
    - debian/patches/CVE-2024-32498-pre2.patch: add type hints.
    - debian/patches/CVE-2024-32498-pre3.patch: consolidate
      create_cow_image and create_image.
    - debian/patches/CVE-2024-32498-1.patch: reject qcow files with
      data-file attributes.
    - debian/patches/CVE-2024-32498-2.patch: check images with
      format_inspector for safety.
    - debian/patches/CVE-2024-32498-3.patch: additional qemu safety
      checking on base images.
    - debian/patches/CVE-2024-32498-4.patch: fix vmdk_allowed_types
      checking.
    - CVE-2024-32498

 -- Marc Deslauriers <email address hidden> Tue, 02 Jul 2024 10:51:41 -0400

Source diff to previous version
CVE-2024-32498 An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom

Version: 2:21.2.4-0ubuntu2.6 2023-09-20 09:08:23 UTC

  nova (2:21.2.4-0ubuntu2.6) focal; urgency=medium

  * d/p/lp1960758-ubuntu-uefi-loader-path.patch: add config option
    'ubuntu_libvirt_uefi_loader_path' to restrict UEFI loaders to
    only those shipped/supported in Ubuntu/Ussuri. (LP: #1960758)

 -- Mauricio Faria de Oliveira <email address hidden> Tue, 25 Jul 2023 17:34:00 -0300

Source diff to previous version
1960758 UEFI libvirt servers can't boot on Ubuntu 20.04 hypervisors with Ussuri/Victoria

Version: 2:21.2.4-0ubuntu2.5 2023-05-23 15:07:16 UTC

  nova (2:21.2.4-0ubuntu2.5) focal-security; urgency=medium

  * SECURITY REGRESSION: Regressions in other projects (LP: #2020111)
    - debian/patches/series: Do not apply CVE-2023-2088.patch until
      patches are ready for all upstream OpenStack projects.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Thu, 18 May 2023 10:52:04 -0400

CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments



About   -   Send Feedback to @ubuntu_updates