[Bug 2020111] Re: CVE-2023-2088 regressions
Felipe Reyes
2020111 at bugs.launchpad.net
Thu Sep 14 12:13:24 UTC 2023
The patch pointed out by Christian is already in the package available
in jammy-updates and focal-yoga cloud archive.
$ git tag --contains 98c3e3707c08a07f7ca5996086b165512f604ad6
25.2.0
25.2.1
$ rmadison nova | grep jammy
nova | 3:25.0.0-0ubuntu1 | jammy | source
nova | 3:25.1.1-0ubuntu1.1 | jammy-security | source
nova | 3:25.2.0-0ubuntu1 | jammy-updates | source # <- this package contains the fix
$ cmadison nova | grep yoga
nova | 3:25.2.0-0ubuntu1~cloud0 | yoga | focal-updates | source # <- this package contains the fix
nova | 3:25.2.0-0ubuntu1~cloud0 | yoga-proposed | focal-proposed | source
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to Ubuntu Cloud Archive.
https://bugs.launchpad.net/bugs/2020111
Title:
CVE-2023-2088 regressions
Status in Ubuntu Cloud Archive:
Fix Released
Status in Ubuntu Cloud Archive antelope series:
Fix Released
Status in Ubuntu Cloud Archive bobcat series:
Fix Released
Status in Ubuntu Cloud Archive victoria series:
Fix Released
Status in Ubuntu Cloud Archive wallaby series:
Fix Released
Status in Ubuntu Cloud Archive xena series:
Fix Released
Status in Ubuntu Cloud Archive yoga series:
Fix Released
Status in Ubuntu Cloud Archive zed series:
Fix Released
Status in cinder package in Ubuntu:
Fix Released
Status in nova package in Ubuntu:
Fix Released
Status in python-glance-store package in Ubuntu:
Fix Released
Status in python-os-brick package in Ubuntu:
Fix Released
Status in cinder source package in Focal:
Fix Released
Status in nova source package in Focal:
Fix Released
Status in python-glance-store source package in Focal:
Fix Released
Status in python-os-brick source package in Focal:
Fix Released
Status in cinder source package in Jammy:
Fix Released
Status in nova source package in Jammy:
Fix Released
Status in python-glance-store source package in Jammy:
Fix Released
Status in python-os-brick source package in Jammy:
Fix Released
Status in cinder source package in Kinetic:
Fix Released
Status in nova source package in Kinetic:
Fix Released
Status in python-glance-store source package in Kinetic:
Fix Released
Status in python-os-brick source package in Kinetic:
Fix Released
Status in cinder source package in Lunar:
Fix Released
Status in nova source package in Lunar:
Fix Released
Status in python-glance-store source package in Lunar:
Fix Released
Status in python-os-brick source package in Lunar:
Fix Released
Status in cinder source package in Mantic:
Fix Released
Status in nova source package in Mantic:
Fix Released
Status in python-glance-store source package in Mantic:
Fix Released
Status in python-os-brick source package in Mantic:
Fix Released
Bug description:
There has been a regression found in at least one project due to the fixes for CVE-2023-2088:
https://bugs.launchpad.net/ironic/+bug/2019892
This may also affect other projects that are yet to be known.
We will be reverting the CVE-2023-2088 patches that have been released
to nova, cinder, python-os-brick, and python-glance-store until
everything is settled upstream in order to prevent regressing our
users.
To manage notifications about this bug go to:
https://bugs.launchpad.net/cloud-archive/+bug/2020111/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list