Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:5113 - Security Advisory
Issued:
2024-08-08
Updated:
2024-08-08

RHSA-2024:5113 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openstack-nova is now available for Red Hat OpenStack
Platform 16.1 (Train).

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

OpenStack Compute (codename Nova) is open source software designed
to provision and manage large networks of virtual machines,creating a
redundant and scalable cloud computing platform. It gives you the software,
control panels, and APIs required to orchestrate a cloud, including running
instances, managing networks, and controlling access through users and
projects.OpenStack Compute strives to be both hardware and hypervisor
agnostic, currently supporting a variety of standard hardware
configurations and seven major hypervisors.

Security Fix(es):

  • Regression VMDK/qcow arbitrary file access (CVE-2024-40767)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

Solution

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenStack for IBM Power 16.1 ppc64le
  • Red Hat OpenStack 16.1 x86_64

Fixes

  • BZ - 2297217 - CVE-2024-40767 openstack-nova: Regression VMDK/qcow arbitrary file access

CVEs

  • CVE-2024-40767

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenStack for IBM Power 16.1

SRPM
openstack-nova-20.4.1-1.20221005193235.el8ost.src.rpm SHA-256: 48396c53a1aa1baca3dbf76bd2251c3f47ceda8305bcfb264777996e01e37c1c
ppc64le
openstack-nova-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 85554c14955fb7623c9c891ba5e98b69e1038f5d79f6aa193ec96aa174258caa
openstack-nova-api-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 6d3020282636ff8f84e7800374d519f7f62e0997c5746d9ec186ffc0cb57b1f4
openstack-nova-common-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 275c375a41208fcfe29b0994d471693cda4352ece478decbd6883566947723f6
openstack-nova-compute-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: de3c552da1f649844a55158f46d7750245412ee0e1171b7d6ba2e686cb2f0884
openstack-nova-conductor-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 9082cf76d0fff664b147bbec4350443ad01159a42700d64c254ca41dbc9282a0
openstack-nova-console-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 38cbb6dfbcd328d3cd396903cb05dd6c656032b0732a747c3c8298ac3824bab5
openstack-nova-migration-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 74acdf26fc2b7fe7fbe88a73cbbedaae0388d55f86731970951b191915f1ff17
openstack-nova-novncproxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 5ad0463f1bca04b12087fb9b7e11f9817bd8e8e1dc22263f96997aab18872fe0
openstack-nova-scheduler-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: cf7a55894739beec355eac535d6478309c4489c0a475f4851cff8749d466bb1a
openstack-nova-serialproxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: e33bbc9541713aeb8c51857462d630c9270db2fe4e4446ebe148f360a8ea655d
openstack-nova-spicehtml5proxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: abf032bbcd53dad41d9bc1d2b94cd7a8e025efaf3a4b901c012a8abeb7c04ca8
python3-nova-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 160f230dfce63cc913df4489c80dd6e84e623361282e61b0c5704d893291bd33

Red Hat OpenStack 16.1

SRPM
openstack-nova-20.4.1-1.20221005193235.el8ost.src.rpm SHA-256: 48396c53a1aa1baca3dbf76bd2251c3f47ceda8305bcfb264777996e01e37c1c
x86_64
openstack-nova-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 85554c14955fb7623c9c891ba5e98b69e1038f5d79f6aa193ec96aa174258caa
openstack-nova-api-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 6d3020282636ff8f84e7800374d519f7f62e0997c5746d9ec186ffc0cb57b1f4
openstack-nova-common-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 275c375a41208fcfe29b0994d471693cda4352ece478decbd6883566947723f6
openstack-nova-compute-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: de3c552da1f649844a55158f46d7750245412ee0e1171b7d6ba2e686cb2f0884
openstack-nova-conductor-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 9082cf76d0fff664b147bbec4350443ad01159a42700d64c254ca41dbc9282a0
openstack-nova-console-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 38cbb6dfbcd328d3cd396903cb05dd6c656032b0732a747c3c8298ac3824bab5
openstack-nova-migration-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 74acdf26fc2b7fe7fbe88a73cbbedaae0388d55f86731970951b191915f1ff17
openstack-nova-novncproxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 5ad0463f1bca04b12087fb9b7e11f9817bd8e8e1dc22263f96997aab18872fe0
openstack-nova-scheduler-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: cf7a55894739beec355eac535d6478309c4489c0a475f4851cff8749d466bb1a
openstack-nova-serialproxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: e33bbc9541713aeb8c51857462d630c9270db2fe4e4446ebe148f360a8ea655d
openstack-nova-spicehtml5proxy-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: abf032bbcd53dad41d9bc1d2b94cd7a8e025efaf3a4b901c012a8abeb7c04ca8
python3-nova-20.4.1-1.20221005193235.el8ost.noarch.rpm SHA-256: 160f230dfce63cc913df4489c80dd6e84e623361282e61b0c5704d893291bd33

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility