RedHat: RHSA-2018-2855:01 Moderate: openstack-nova security and bug fix
Summary
OpenStack Compute (nova) launches and schedules large networks of virtual
machines, creating a redundant and scalable cloud computing platform.
Compute provides the software, control panels, and APIs required to
orchestrate a cloud, including running virtual machine instances and
controlling access through users and projects.
Security Fix(es):
* openstack-nova: Swapping encrypted volumes can allow an attacker to
corrupt the LUKS header causing a denial of service in the host
(CVE-2017-18191)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
Bug Fix(es):
* This update fixes a race condition that could generate error messages and
cause migration failures during nova live migrations.
Prior to this update, if a domain was already cleaned out by periodic
tasks, undefining the domain source during a live migration sometimes
generated a "Domain not found (Code=42)" error. (BZ#1614325)
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2017-18191 https://access.redhat.com/security/updates/classification/#moderate
Package List
Red Hat OpenStack Platform 9.0:
Source:
openstack-nova-13.1.4-24.el7ost.src.rpm
noarch:
openstack-nova-13.1.4-24.el7ost.noarch.rpm
openstack-nova-api-13.1.4-24.el7ost.noarch.rpm
openstack-nova-cells-13.1.4-24.el7ost.noarch.rpm
openstack-nova-cert-13.1.4-24.el7ost.noarch.rpm
openstack-nova-common-13.1.4-24.el7ost.noarch.rpm
openstack-nova-compute-13.1.4-24.el7ost.noarch.rpm
openstack-nova-conductor-13.1.4-24.el7ost.noarch.rpm
openstack-nova-console-13.1.4-24.el7ost.noarch.rpm
openstack-nova-migration-13.1.4-24.el7ost.noarch.rpm
openstack-nova-network-13.1.4-24.el7ost.noarch.rpm
openstack-nova-novncproxy-13.1.4-24.el7ost.noarch.rpm
openstack-nova-scheduler-13.1.4-24.el7ost.noarch.rpm
openstack-nova-serialproxy-13.1.4-24.el7ost.noarch.rpm
openstack-nova-spicehtml5proxy-13.1.4-24.el7ost.noarch.rpm
python-nova-13.1.4-24.el7ost.noarch.rpm
python-nova-tests-13.1.4-24.el7ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for openstack-nova is now available for Red Hat OpenStackPlatform 9.0 (Mitaka).Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat OpenStack Platform 9.0 - noarch
Bugs Fixed
1545330 - I/O latency of cinder volume after live migration increases
1546937 - CVE-2017-18191 openstack-nova: Swapping encrypted volumes can allow an attacker to corrupt the LUKS header causing a denial of service in the host
1569952 - preallocate_images = space is not honoured when using qcow2