RHSA-2024:5097HighCVSS 5.5
Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-40767 — openstack-nova: Regression VMDK/qcow arbitrary file access
🎯 Affected products14
- Red Hat OpenStack Platform 16.2
- openstack-nova-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-1:20.6.2-2.20230814165229.el8ost.src as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-api-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-common-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-compute-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-conductor-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-console-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-migration-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-novncproxy-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-scheduler-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-serialproxy-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- openstack-nova-spicehtml5proxy-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
- python3-nova-1:20.6.2-2.20230814165229.el8ost.noarch as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258