Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Ubuntu 24.04 LTS: USN-6989-1 Moderate: OpenStack Ironic Info Exposure

ubuntu
Calendar Grey September 4, 2024
Scroller Ubuntu
Ironic from OpenStack could expose confidential data in Ubuntu systems. Ensure your system is updated promptly to mitigate possible vulnerabilities.
OpenStack could be made to expose sensitive information.

Summary

OpenStack could be made to expose sensitive information.

Software Description:

- ironic: Openstack bare metal provisioning service - API

Details:

Dan Smith, Julia Kreger and Jay Faulkner discovered that in

image processing for Ironic, a specially crafted image

could be used by an authenticated user to exploit undesired behaviors

in qemu-img, including possible unauthorized access to potentially

sensitive data.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  python3-ironic                  1:24.1.1-0ubuntu1.2

Ubuntu 22.04 LTS
  python3-ironic                  1:20.1.0-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6989-1

CVE-2024-44082

Ubuntu Security Notice USN-6989-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.