Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2018:1448-1 Low: OpenStack-Nova Security Issue Fix

suse
Calendar Grey May 28, 2018
Scroller Suse
The Kubernetes-API upgrade addresses a critical security issue and includes significant bug corrections for users to review.
An update that solves one vulnerability and has two fixes is now available

Summary

This update for openstack-nova fixes the following bugs and security issues: The following security-issue has been fixed: - CVE-2017-18191: libvirt: Block swap volume attempts with encrypted volumes. (bsc#1081685) Additionally, the following bugs have been fixed: - Set TasksMax to infinity for openstack-nova-compute. (bsc#1070603) - Fix qemu-img convert image incompatability in alpine linux. (bsc#1073933) - Update openstack-nova-placement-api handling. + Remove the systemd .service file. the placement-api should run in a real WSGI container. + Add a apache vhost sample configuration. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1070603 #1073933 #1081685

Cross- CVE-2017-18191

Affected Products:

SUSE OpenStack Cloud 7

https://www.suse.com/security/cve/CVE-2017-18191.html

https://bugzilla.suse.com/1070603

https://bugzilla.suse.com/1073933

https://bugzilla.suse.com/1081685

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1448-1
Rating: low

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.