Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
172

Ubuntu 20.04 18.04 OpenStack Glance Security Flaws USN-8199-1

Several security issues were fixed in OpenStack Glance.. ========================================================================== Ubuntu Security Notice USN-8199-1 April 22, 2026 glance vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenStack Glance. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Martin Kaesberger discovered that OpenStack Glance's image processing could return the contents of arbitrary files. An attacker could possibly use this issue to exfiltrate sensitive data. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-32498) Hyeongeun Ji and Abhishek Kekane discovered several server-side request forgery vulnerabilities in OpenStack Glance's image import. An attacker could possibly use this issue to bypass URL validation checks and redirect to internal services. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-34881) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-api 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-common 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro python3-glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-api 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-common 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-registry 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro python-glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-api 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-common 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-glare 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-registry 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro python-glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8199-1 CVE-2024-32498, CVE-2026-34881 . Review of Ubuntu's USN-8199-1 highlighting fixed security issues in OpenStack Glance affecting multiple LTS versions.. OpenStack Glance security, Ubuntu vulnerabilities, image processing issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 27, 2026 Important Ubuntu
172

Ubuntu 25.10 OpenStack Glance Noteworthy SSRF Vulnerability USN-8111-2

OpenStack Glance could be made to perform server-side request forgery. ========================================================================== Ubuntu Security Notice USN-8111-1 March 19, 2026 glance vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: OpenStack Glance could be made to perform server-side request forgery Software Description: - glance: OpenStack Image Registry and Delivery Service Details: It was discovered that OpenStack Glance was incorrectly validating the IP addresses and the redirect destination URL when downloading or importing images from a remote source. An attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 glance 2:31.0.0-0ubuntu1.2 glance-api 2:31.0.0-0ubuntu1.2 glance-common 2:31.0.0-0ubuntu1.2 python-glance-doc 2:31.0.0-0ubuntu1.2 python3-glance 2:31.0.0-0ubuntu1.2 Ubuntu 24.04 LTS glance 2:28.1.0-0ubuntu1.2 glance-api 2:28.1.0-0ubuntu1.2 glance-common 2:28.1.0-0ubuntu1.2 python-glance-doc 2:28.1.0-0ubuntu1.2 python3-glance 2:28.1.0-0ubuntu1.2 Ubuntu 22.04 LTS glance 2:24.2.1-0ubuntu1.4 glance-api 2:24.2.1-0ubuntu1.4 glance-common 2:24.2.1-0ubuntu1.4 python-glance-doc 2:24.2.1-0ubuntu1.4 python3-glance 2:24.2.1-0ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8111-1 https://bugs.launchpad.net/glance/+bug/2138602 PackageInformation: https://launchpad.net/ubuntu/+source/glance/2:31.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:28.1.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:24.2.1-0ubuntu1.4 . Update your Ubuntu systems to fix important OpenStack Glance server-side request forgery vulnerability issues effectively.. OpenStack Glance, Ubuntu 25.10, security advisory, server-side request forgery, image registry. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 19, 2026 Important Ubuntu
197

Debian 11: DLA-3872-1 Critical: Glance Arbitrary File Disclosure

Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3872-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thomas Goirand September 05, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : glance Version : 2:21.1.0-1+deb11u2 CVE ID : CVE-2024-32498 Debian Bug : 1074761 Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. For Debian 11 bullseye, this problem has been fixed in version 2:21.1.0-1+deb11u2. We recommend that you upgrade your glance packages. For the detailed security status of glance please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/glance Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Urgent notice for Glance users regarding a critical security vulnerability; please update without delay to safeguard against potential data leaks.. OpenStack, Glance Update, Debian LTS Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 04, 2024 Critical Debian LTS
87

Debian: DSA-5755-1 Moderate: Glance Arbitrary File Disclosure

Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5755-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 21, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : glance CVE ID : CVE-2024-32498 Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files. For the stable distribution (bookworm), this problem has been fixed in version 2:25.1.0-2+deb12u1. We recommend that you upgrade your glance packages. For the detailed security status of glance please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/glance Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Defective QCOW2 disk images may reveal sensitive data; Ubuntu recommends urgent updates for glance software.. OpenStack Security, Debian Advisory, Glance Security, File Disclosure Risk. . LinuxSecurity.com Team

Calendar%202 Aug 21, 2024 Debian
172

Ubuntu 24.04 LTS Advisory USN-6883-1: Glance File Access Risk

OpenStack Glance would allow unintended access to files over the network.. ========================================================================== Ubuntu Security Notice USN-6883-1 July 08, 2024 glance vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenStack Glance would allow unintended access to files over the network. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Martin Kaesberger discovered that Glance incorrectly handled QCOW2 image processing. An authenticated user could use this issue to access arbitrary files on the server, possibly exposing sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS glance-common 2:28.0.1-0ubuntu1.2 Ubuntu 23.10 glance-common 2:27.0.0-0ubuntu1.2 Ubuntu 22.04 LTS glance-common 2:24.2.1-0ubuntu1.2 Ubuntu 20.04 LTS glance-common 2:20.2.0-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6883-1 CVE-2024-32498 Package Information: https://launchpad.net/ubuntu/+source/glance/2:28.0.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:27.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:24.2.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/glance/2:20.2.0-0ubuntu1.2 . Addressing a vulnerability in OpenStack Glance, this advisory emphasizes the need for immediate updates to prevent unauthorized file exposure over the network. OpenStack Image Registry, Glance Security Update, Ubuntu Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 08, 2024 Critical Ubuntu
87

Debian Bullseye: DSA-5336-1 High: Glance Information Disclosure

Guillaume Espanel, Pierre Libeau, Arnaud Morin and Damien Rannou discovered that missing input sanitising in the handling of VMDK images in Glance, the OpenStack image registry and delivery service, may result in information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5336-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 01, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : glance CVE ID : CVE-2022-47951 Debian Bug : 1029563 Guillaume Espanel, Pierre Libeau, Arnaud Morin and Damien Rannou discovered that missing input sanitising in the handling of VMDK images in Glance, the OpenStack image registry and delivery service, may result in information disclosure. For the stable distribution (bullseye), this problem has been fixed in version 2:21.0.0-2+deb11u1. We recommend that you upgrade your glance packages. For the detailed security status of glance please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/glance Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Lack of proper input validation in Glance's processing of VMDK files may result in unintended information leakage. Suggested action: implement necessary updates.. Glance Security, Debian Update, OpenStack, Data Protection, Input Validation. . LinuxSecurity.com Team

Calendar%202 Feb 01, 2023 Debian
172

Ubuntu 22.10 USN-5835-2 Moderate OpenStack Glance Info Leak

OpenStack Glance could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-5835-2 January 31, 2023 glance vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenStack Glance could be made to expose sensitive information. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that OpenStack Glance incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: glance-common 2:25.0.0-0ubuntu1.1 Ubuntu 22.04 LTS: glance-common 2:24.1.0-0ubuntu1.1 Ubuntu 20.04 LTS: glance-common 2:20.2.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5835-2 https://ubuntu.com/security/notices/USN-5835-1 CVE-2022-47951 Package Information: https://launchpad.net/ubuntu/+source/glance/2:25.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/glance/2:24.1.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/glance/2:20.2.0-0ubuntu1.1 . OpenStack Glance security flaw permits leakage of confidential data; ensure you’re informed about the latest patches.. OpenStack Security, Glance Update, Information Exposure, Ubuntu Advisory. . LinuxSecurity.com Team

Calendar%202 Jan 31, 2023 Ubuntu
197

Debian 10 Buster DLA-3300-1 Important: Glance Data Exposure Risk

An issue was discovered in Glance, OpenStack Image Registry and Delivery Service - Daemons. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3300-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta January 31, 2023 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : glance Version : 2:17.0.0-5+deb10u1 CVE ID : CVE-2022-47951 Debian Bug : 1029563 An issue was discovered in Glance, OpenStack Image Registry and Delivery Service - Daemons. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. For Debian 10 buster, this problem has been fixed in version 2:17.0.0-5+deb10u1. We recommend that you upgrade your glance packages. For the detailed security status of glance please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/glance Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An essential patch for Glance in Debian LTS addresses a vulnerability that could expose confidential information. It is advised to perform the update.. Glance Security Update, OpenStack Security, Debian Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 30, 2023 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200