First published: Mon Apr 07 2025(Updated: )
Ironic is a project which aims to provision bare metal (as opposed to<br>virtual) machines by leveraging common technologies such as PXE boot and<br>IPMI to cover a wide range of hardware, while supporting pluggable drivers<br>to allow vendor-specific functionality to be added.Bare Metal provisioning<br>for OpenStack<br>Security Fix(es):<br><li> Lack of checksum validation on images (CVE-2024-47211)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Services on OpenShift | ||
redhat/openstack-ironic | <17.1.1-17.1.20241122190825.c31db88.el9 | 17.1.1-17.1.20241122190825.c31db88.el9 |
redhat/openstack-ironic-api | <17.1.1-17.1.20241122190825.c31db88.el9 | 17.1.1-17.1.20241122190825.c31db88.el9 |
redhat/openstack-ironic-common | <17.1.1-17.1.20241122190825.c31db88.el9 | 17.1.1-17.1.20241122190825.c31db88.el9 |
redhat/openstack-ironic-conductor | <17.1.1-17.1.20241122190825.c31db88.el9 | 17.1.1-17.1.20241122190825.c31db88.el9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:3482 is classified as moderate.
To fix RHSA-2025:3482, upgrade the affected packages to version 17.1.1-17.1.20241122190825.c31db88.el9.
RHSA-2025:3482 affects Red Hat OpenStack Services on OpenShift and specific OpenStack Ironic components.
The specific packages affected by RHSA-2025:3482 include openstack-ironic, openstack-ironic-api, openstack-ironic-common, and openstack-ironic-conductor.
Yes, the known fix release for RHSA-2025:3482 is version 17.1.1-17.1.20241122190825.c31db88.el9.