PT-2024-30939 · Openstack+4 · Openstack Ironic+5

Dan Smith

+2

·

Published

2024-07-02

·

Updated

2026-01-22

·

CVE-2024-44082

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Ironic versions prior to 26.0.1 Ironic-python-agent versions prior to 9.13.1
Description The issue concerns a vulnerability in image processing, where a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, potentially leading to unauthorized access to sensitive data.
Recommendations For OpenStack Ironic versions prior to 26.0.1, update to version 26.0.1 or later to resolve the issue. For Ironic-python-agent versions prior to 9.13.1, update to version 9.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted images in the image processing functionality until a patch is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-01022
CVE-2024-44082
RHSA-2024:7941
RHSA-2024:8694
RHSA-2024:9982
RHSA-2025:0204
USN-6989-1

Affected Products

Debian
Ironic-Python-Agent
Linuxmint
Openstack Ironic
Red Os
Ubuntu