-
Notifications
You must be signed in to change notification settings - Fork 530
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add releasenote for CVE-2024-32498 fix
Related-Bug: #2059809 Change-Id: I3259dd013ba5e3fefd0e172bf0e7cc502158c8db
- Loading branch information
1 parent
0d8e79b
commit 867d1dd
Showing
1 changed file
with
17 additions
and
0 deletions.
There are no files selected for viewing
17 changes: 17 additions & 0 deletions
17
releasenotes/notes/bug-2059809-disallow-qcow2-datafile-5d5ff4dbd590c911.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
--- | ||
security: | ||
- | | ||
Images in the qcow2 format with an external data file are now | ||
rejected from glance because such images could be used in an | ||
exploit to expose host information. See `Bug #2059809 | ||
<https://bugs.launchpad.net/glance/+bug/2059809>`_ for details. | ||
fixes: | ||
- | | ||
`Bug #2059809 <https://bugs.launchpad.net/glance/+bug/2059809>`_: | ||
Fixed issue where a qcow2 format image with an external data file | ||
could expose host information. Such an image format with an external | ||
data file will be rejected from glance. To achieve the same, | ||
format_inspector has been extended by adding safety checks for qcow2 | ||
and vmdk files in glance. Unsafe qcow and vmdk files will be rejected | ||
by pre-examining them with a format inspector to ensure safe | ||
configurations prior to any qemu-img operations. |