A flaw was found in the OpenStack Compute (nova), Block Storage (cinder) and Image (glance) services in the way user-uploaded image files are validated through QEMU disk image utility (qemu-img). A QCOW2 or VMDK disk image containing a maliciously crafted reference could lead to an information disclosure vulnerability where the user can effectively read any file on the compute host that QEMU is allowed to read, potential file overwrite and unbounded memory/CPU consumption.
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2024:4272 https://access.redhat.com/errata/RHSA-2024:4272
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2024:4273 https://access.redhat.com/errata/RHSA-2024:4273
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 8 Via RHSA-2024:4274 https://access.redhat.com/errata/RHSA-2024:4274
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2024:4425 https://access.redhat.com/errata/RHSA-2024:4425