Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in OpenStack Glance.. ========================================================================== Ubuntu Security Notice USN-8199-1 April 22, 2026 glance vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenStack Glance. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Martin Kaesberger discovered that OpenStack Glance's image processing could return the contents of arbitrary files. An attacker could possibly use this issue to exfiltrate sensitive data. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-32498) Hyeongeun Ji and Abhishek Kekane discovered several server-side request forgery vulnerabilities in OpenStack Glance's image import. An attacker could possibly use this issue to bypass URL validation checks and redirect to internal services. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-34881) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-api 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-common 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro python3-glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-api 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-common 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-registry 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro python-glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-api 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-common 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-glare 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-registry 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro python-glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8199-1 CVE-2024-32498, CVE-2026-34881 . Review of Ubuntu's USN-8199-1 highlighting fixed security issues in OpenStack Glance affecting multiple LTS versions.. OpenStack Glance security, Ubuntu vulnerabilities, image processing issues. . Severity: Important. LinuxSecurity.com Team
OpenStack Glance could be made to perform server-side request forgery. ========================================================================== Ubuntu Security Notice USN-8111-1 March 19, 2026 glance vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: OpenStack Glance could be made to perform server-side request forgery Software Description: - glance: OpenStack Image Registry and Delivery Service Details: It was discovered that OpenStack Glance was incorrectly validating the IP addresses and the redirect destination URL when downloading or importing images from a remote source. An attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 glance 2:31.0.0-0ubuntu1.2 glance-api 2:31.0.0-0ubuntu1.2 glance-common 2:31.0.0-0ubuntu1.2 python-glance-doc 2:31.0.0-0ubuntu1.2 python3-glance 2:31.0.0-0ubuntu1.2 Ubuntu 24.04 LTS glance 2:28.1.0-0ubuntu1.2 glance-api 2:28.1.0-0ubuntu1.2 glance-common 2:28.1.0-0ubuntu1.2 python-glance-doc 2:28.1.0-0ubuntu1.2 python3-glance 2:28.1.0-0ubuntu1.2 Ubuntu 22.04 LTS glance 2:24.2.1-0ubuntu1.4 glance-api 2:24.2.1-0ubuntu1.4 glance-common 2:24.2.1-0ubuntu1.4 python-glance-doc 2:24.2.1-0ubuntu1.4 python3-glance 2:24.2.1-0ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8111-1 https://bugs.launchpad.net/glance/+bug/2138602 PackageInformation: https://launchpad.net/ubuntu/+source/glance/2:31.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:28.1.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:24.2.1-0ubuntu1.4 . Update your Ubuntu systems to fix important OpenStack Glance server-side request forgery vulnerability issues effectively.. OpenStack Glance, Ubuntu 25.10, security advisory, server-side request forgery, image registry. . Severity: Important. LinuxSecurity.com Team
Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3872-1
Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5755-1
OpenStack Glance would allow unintended access to files over the network.. ========================================================================== Ubuntu Security Notice USN-6883-1 July 08, 2024 glance vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenStack Glance would allow unintended access to files over the network. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Martin Kaesberger discovered that Glance incorrectly handled QCOW2 image processing. An authenticated user could use this issue to access arbitrary files on the server, possibly exposing sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS glance-common 2:28.0.1-0ubuntu1.2 Ubuntu 23.10 glance-common 2:27.0.0-0ubuntu1.2 Ubuntu 22.04 LTS glance-common 2:24.2.1-0ubuntu1.2 Ubuntu 20.04 LTS glance-common 2:20.2.0-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6883-1 CVE-2024-32498 Package Information: https://launchpad.net/ubuntu/+source/glance/2:28.0.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:27.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:24.2.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:20.2.0-0ubuntu1.2 . Addressing a vulnerability in OpenStack Glance, this advisory emphasizes the need for immediate updates to prevent unauthorized file exposure over the network. OpenStack Image Registry, Glance Security Update, Ubuntu Advisory. . Severity: Critical. LinuxSecurity.com Team
Guillaume Espanel, Pierre Libeau, Arnaud Morin and Damien Rannou discovered that missing input sanitising in the handling of VMDK images in Glance, the OpenStack image registry and delivery service, may result in information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5336-1
OpenStack Glance could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-5835-2 January 31, 2023 glance vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenStack Glance could be made to expose sensitive information. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that OpenStack Glance incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: glance-common 2:25.0.0-0ubuntu1.1 Ubuntu 22.04 LTS: glance-common 2:24.1.0-0ubuntu1.1 Ubuntu 20.04 LTS: glance-common 2:20.2.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5835-2 https://ubuntu.com/security/notices/USN-5835-1 CVE-2022-47951 Package Information: https://launchpad.net/ubuntu/+source/glance/2:25.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/glance/2:24.1.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/glance/2:20.2.0-0ubuntu1.1 . OpenStack Glance security flaw permits leakage of confidential data; ensure you’re informed about the latest patches.. OpenStack Security, Glance Update, Information Exposure, Ubuntu Advisory. . LinuxSecurity.com Team
An issue was discovered in Glance, OpenStack Image Registry and Delivery Service - Daemons. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3300-1
Get the latest Linux and open source security news straight to your inbox.