USN-6882-2: Cinder regression
USN-6882-1 fixed vulnerabilities in Cinder. The update caused a regression in certain environments due to incorrect privilege handling. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image processing. An authenticated user could use this issue to access arbitrary files on the server, possibly exposing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6882-2?
USN-6882-2 addresses a regression issue related to incorrect privilege handling in Cinder, which may affect certain environments.
How do I fix USN-6882-2?
To fix USN-6882-2, update the python3-cinder package to the specified remedy version for your Ubuntu release.
Which versions of python3-cinder are affected by USN-6882-2?
USN-6882-2 affects python3-cinder versions 2:24.0.0-0ubuntu1.3, 2:20.3.1-0ubuntu1.5, and 2:16.4.2-0ubuntu2.9 depending on the Ubuntu version.
What environments are impacted by USN-6882-2?
Certain environments running specific versions of Ubuntu with Cinder may experience issues due to the regression fixed in USN-6882-2.
Has USN-6882-2 replaced any previous advisories?
Yes, USN-6882-2 is an update to USN-6882-1, which initially addressed vulnerabilities but introduced a regression.