UbuntuUpdates.org

Package "nova-api-metadata"

Name: nova-api-metadata

Description:

OpenStack Compute - metadata API frontend

Latest version: 2:21.2.4-0ubuntu2.11
Release: focal (20.04)
Level: security
Repository: universe
Head package: nova
Homepage: https://launchpad.net/nova

Links


Download "nova-api-metadata"


Other versions of "nova-api-metadata" in Focal

Repository Area Version
base universe 2:21.0.0~b3~git2020041013.57ff308d6d-0ubuntu2
updates universe 2:21.2.4-0ubuntu2.13
proposed universe 2:21.2.4-0ubuntu2.14

Changelog

Version: 2:21.2.4-0ubuntu2.11 2024-07-23 19:07:33 UTC

  nova (2:21.2.4-0ubuntu2.11) focal-security; urgency=medium

  * SECURITY UPDATE: Incomplete file access fix and regression for QCOW2
    backing files and VMDK flat descriptors
    - debian/patches/CVE-2024-40767-pre1.patch: port format inspector tests
      from glance.
    - debian/patches/CVE-2024-40767-pre2.patch: reproduce iso regression
      with deep format inspection.
    - debian/patches/CVE-2024-40767-pre3.patch: add iso file format
      inspector.
    - debian/patches/CVE-2024-40767-pre4.patch: fix qemu-img version
      dependent tests.
    - debian/patches/CVE-2024-40767-pre5.patch: stabilize iso format unit
      tests.
    - debian/patches/CVE-2024-40767.patch: change force_format strategy to
      catch mismatches.
    - CVE-2024-40767
  * Replace CVE-2024-32498 patches with final versions from git.
    - debian/patches/CVE-2024-32498-*
  * debian/control: added qemu-utils to Build-Depends so qemu-img is
    available for new tests.
  * Note: this package does _not_ contain the changes from
    2:21.2.4-0ubuntu2.9 and 2:21.2.4-0ubuntu2.10 in focal-proposed.

 -- Marc Deslauriers <email address hidden> Wed, 17 Jul 2024 14:01:19 -0400

Source diff to previous version
CVE-2024-32498 An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom

Version: 2:21.2.4-0ubuntu2.8 2024-07-08 18:07:43 UTC

  nova (2:21.2.4-0ubuntu2.8) focal-security; urgency=medium

  * SECURITY UPDATE: Arbitrary file access via custom QCOW2 external data
    (LP: #2059809)
    - debian/patches/CVE-2024-32498-pre1.patch: create qcow2 disks with the
      correct size without extending.
    - debian/patches/CVE-2024-32498-pre2.patch: add type hints.
    - debian/patches/CVE-2024-32498-pre3.patch: consolidate
      create_cow_image and create_image.
    - debian/patches/CVE-2024-32498-1.patch: reject qcow files with
      data-file attributes.
    - debian/patches/CVE-2024-32498-2.patch: check images with
      format_inspector for safety.
    - debian/patches/CVE-2024-32498-3.patch: additional qemu safety
      checking on base images.
    - debian/patches/CVE-2024-32498-4.patch: fix vmdk_allowed_types
      checking.
    - CVE-2024-32498

 -- Marc Deslauriers <email address hidden> Tue, 02 Jul 2024 10:51:41 -0400

Source diff to previous version
CVE-2024-32498 An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom

Version: 2:21.2.4-0ubuntu2.5 2023-05-23 14:07:25 UTC

  nova (2:21.2.4-0ubuntu2.5) focal-security; urgency=medium

  * SECURITY REGRESSION: Regressions in other projects (LP: #2020111)
    - debian/patches/series: Do not apply CVE-2023-2088.patch until
      patches are ready for all upstream OpenStack projects.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Thu, 18 May 2023 10:52:04 -0400

Source diff to previous version
CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments

Version: 2:21.2.4-0ubuntu2.4 2023-05-14 18:07:16 UTC

  nova (2:21.2.4-0ubuntu2.4) focal-security; urgency=medium

  * SECURITY REGRESSION: Regression with volume drivers (LP: #2019460)
    - debian/patches/CVE-2023-2088.patch: Updated to add missing force
      parameter to various volume drivers.

 -- Corey Bryant <email address hidden> Sat, 13 May 2023 09:56:20 -0400

Source diff to previous version
2019460 nova-compute 23.2.2-0ubuntu1~cloud2 unable to detach volumes
CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments

Version: 2:21.2.4-0ubuntu2.3 2023-05-11 19:07:16 UTC

  nova (2:21.2.4-0ubuntu2.3) focal-security; urgency=medium

  * SECURITY UPDATE: Unauthorized File Access
    - debian/patches/CVE-2023-2088.patch: Use force=True for os-brick
      disconnect during delete.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Tue, 09 May 2023 16:59:35 -0400

CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments



About   -   Send Feedback to @ubuntu_updates