RHSA-2025:0204: Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update
Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update
Other sources
Ironic is a project which aims to provision bare metal (as opposed to<br>virtual) machines by leveraging common technologies such as PXE boot and<br>IPMI to cover a wide range of hardware, while supporting pluggable drivers<br>to allow vendor-specific functionality to be added.Bare Metal provisioning<br>for OpenStack<br>Security Fix(es):<br><li> Specially crafted image may allow authenticated users to gain access to</li> potentially sensitive data (CVE-2024-44082)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0204?
The severity of RHSA-2025:0204 is classified as important.
How do I fix RHSA-2025:0204?
To fix RHSA-2025:0204, update the affected packages to version 13.0.8-2.20230713045150.d10fd5c.el8.
Which software packages are affected by RHSA-2025:0204?
The affected software packages include openstack-ironic, openstack-ironic-api, openstack-ironic-common, and openstack-ironic-conductor.
What does RHSA-2025:0204 address?
RHSA-2025:0204 addresses security vulnerabilities in the Red Hat OpenStack Platform 16.2 specifically related to Ironic.
Is Red Hat OpenStack mandatory to address RHSA-2025:0204?
Yes, it is necessary to apply RHSA-2025:0204 for installations of Red Hat OpenStack Platform that use the Ironic service.