USN-6989-1: OpenStack vulnerability
Dan Smith, Julia Kreger and Jay Faulkner discovered that in image processing for Ironic, a specially crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6989-1?
The severity of USN-6989-1 is classified as high due to the potential for unauthorized access to sensitive data.
How do I fix USN-6989-1?
To fix USN-6989-1, update the python3-ironic package to version 1:24.1.1-0ubuntu1.2 for Ubuntu 24.04 or version 1:20.1.0-0ubuntu1.2 for Ubuntu 22.04.
Who discovered the vulnerability USN-6989-1?
USN-6989-1 was discovered by Dan Smith, Julia Kreger, and Jay Faulkner.
What products are affected by USN-6989-1?
USN-6989-1 affects the python3-ironic package on Ubuntu 22.04 and 24.04.
What kind of attack does USN-6989-1 facilitate?
USN-6989-1 facilitates the exploitation of qemu-img through specially crafted images, allowing for possible unauthorized access.