First published: Wed Jan 22 2025(Updated: )
Ironic is a project which aims to provision bare metal (as opposed to<br>virtual) machines by leveraging common technologies such as PXE boot and<br>IPMI to cover a wide range of hardware, while supporting pluggable drivers<br>to allow vendor-specific functionality to be added.Bare Metal provisioning<br>for OpenStack<br>Security Fix(es):<br><li> Lack of checksum validation on images (CVE-2024-47211)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openstack-ironic | <21.4.5-18.0.20241207142602.9213ccd.el9 | 21.4.5-18.0.20241207142602.9213ccd.el9 |
redhat/openstack-ironic-api | <21.4.5-18.0.20241207142602.9213ccd.el9 | 21.4.5-18.0.20241207142602.9213ccd.el9 |
redhat/openstack-ironic-common | <21.4.5-18.0.20241207142602.9213ccd.el9 | 21.4.5-18.0.20241207142602.9213ccd.el9 |
redhat/openstack-ironic-conductor | <21.4.5-18.0.20241207142602.9213ccd.el9 | 21.4.5-18.0.20241207142602.9213ccd.el9 |
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:0439 is classified as moderate.
To fix RHSA-2025:0439, update the affected packages to version 21.4.5-18.0.20241207142602.9213ccd.el9.
RHSA-2025:0439 affects Red Hat OpenStack Services on OpenShift and several packages including openstack-ironic and openstack-ironic-api.
The recommended package updates for RHSA-2025:0439 are openstack-ironic, openstack-ironic-api, openstack-ironic-common, and openstack-ironic-conductor to version 21.4.5-18.0.20241207142602.9213ccd.el9.
RHSA-2025:0439 was announced in 2025.