USN-6073-8: Nova regression
USN-6073-3 fixed a vulnerability in Nova. Unfortunately the update introduced a regression with detaching volumes. The security fix has been removed pending further investigation. We apologize for the inconvenience. Original advisory details: Jan Wasilewski and Gorka Eguileor discovered that Nova incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information. This update may require configuration changes to be completely effective, please see the upstream advisory for more information: https://security.openstack.org/ossa/OSSA-2023-003.html
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability fixed by USN-6073-3?
The vulnerability fixed by USN-6073-3 is a regression with detaching volumes in Nova.
What was the security fix in USN-6073-3?
The security fix in USN-6073-3 addressed a vulnerability related to Nova.
What is the impact of the regression introduced in USN-6073-3?
The regression introduced in USN-6073-3 affects the ability to detach volumes in Nova.
What is the remedy for the regression in USN-6073-3?
The security fix for the regression in USN-6073-3 has been removed pending further investigation.
What versions of Ubuntu are affected by the regression?
The regression affects Ubuntu versions 23.04, 22.10, 22.04, and 20.04.