Bug 2278663 (2024-emu, CVE-2024-32498) - CVE-2024-32498 OpenStack: malicious qcow2/vmdk images
Summary: CVE-2024-32498 OpenStack: malicious qcow2/vmdk images
Keywords:
Status: NEW
Alias: 2024-emu, CVE-2024-32498
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2278665 2278666 2278667 2278668 2278669 2278670 2294740 2295197 2295307 2295308 2295309
Blocks: 2278671
TreeView+ depends on / blocked
 
Reported: 2024-05-02 16:04 UTC by Mauro Matteo Cascella
Modified: 2025-02-07 20:12 UTC (History)
30 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:4272 0 None None None 2024-07-02 16:41:42 UTC
Red Hat Product Errata RHSA-2024:4273 0 None None None 2024-07-02 16:43:55 UTC
Red Hat Product Errata RHSA-2024:4274 0 None None None 2024-07-02 16:44:07 UTC
Red Hat Product Errata RHSA-2024:4425 0 None None None 2024-07-09 12:11:45 UTC

Description Mauro Matteo Cascella 2024-05-02 16:04:55 UTC
A flaw was found in the OpenStack Compute (nova), Block Storage (cinder) and Image (glance) services in the way user-uploaded image files are validated through QEMU disk image utility (qemu-img). A QCOW2 or VMDK disk image containing a maliciously crafted reference could lead to an information disclosure vulnerability where the user can effectively read any file on the compute host that QEMU is allowed to read, potential file overwrite and unbounded memory/CPU consumption.

Comment 7 errata-xmlrpc 2024-07-02 16:41:40 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 17.1 for RHEL 9

Via RHSA-2024:4272 https://access.redhat.com/errata/RHSA-2024:4272

Comment 8 errata-xmlrpc 2024-07-02 16:43:53 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2024:4273 https://access.redhat.com/errata/RHSA-2024:4273

Comment 9 errata-xmlrpc 2024-07-02 16:44:05 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 17.1 for RHEL 8

Via RHSA-2024:4274 https://access.redhat.com/errata/RHSA-2024:4274

Comment 15 errata-xmlrpc 2024-07-09 12:11:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.1

Via RHSA-2024:4425 https://access.redhat.com/errata/RHSA-2024:4425


Note You need to log in before you can comment on or make changes to this bug.