USN-6989-1: OpenStack vulnerability

Published Sep 4, 2024
·
Updated

Dan Smith, Julia Kreger and Jay Faulkner discovered that in image processing for Ironic, a specially crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data.

Affected Software

4 affected componentsFixes available
All of the following
ubuntu/python3-ironic<1:24.1.1-0ubuntu1.2
1:24.1.1-0ubuntu1.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3-ironic<1:20.1.0-0ubuntu1.2
1:20.1.0-0ubuntu1.2
Ubuntu Ubuntu=22.04

Event History

Sep 4, 2024
Advisory Published
via Ubuntu·12:00 AM

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of USN-6989-1?

The severity of USN-6989-1 is classified as high due to the potential for unauthorized access to sensitive data.

2

How do I fix USN-6989-1?

To fix USN-6989-1, update the python3-ironic package to version 1:24.1.1-0ubuntu1.2 for Ubuntu 24.04 or version 1:20.1.0-0ubuntu1.2 for Ubuntu 22.04.

3

Who discovered the vulnerability USN-6989-1?

USN-6989-1 was discovered by Dan Smith, Julia Kreger, and Jay Faulkner.

4

What products are affected by USN-6989-1?

USN-6989-1 affects the python3-ironic package on Ubuntu 22.04 and 24.04.

5

What kind of attack does USN-6989-1 facilitate?

USN-6989-1 facilitates the exploitation of qemu-img through specially crafted images, allowing for possible unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203