USN-5866-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5866-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5866-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5866-1
Related
Published
2023-02-13T10:41:19.347287Z
Modified
2023-02-13T10:41:19.347287Z
Summary
nova vulnerabilities
Details

It was discovered that Nova did not properly manage data logged into the log file. An attacker with read access to the service's logs could exploit this issue and may obtain sensitive information. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)

It was discovered that Nova did not properly handle attaching and reattaching the encrypted volume. An attacker could possibly use this issue to perform a denial of service attack. This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18191)

It was discovered that Nova did not properly handle the updation of domain XML after live migration. An attacker could possibly use this issue to corrupt the volume or perform a denial of service attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-17376)

It was discovered that Nova was not properly validating the URL passed to noVNC. An attacker could possibly use this issue by providing malicious URL to the noVNC proxy to redirect to any desired URL. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-3654)

It was discovered that Nova did not properly handle changes in the neutron port of vnic_type type. An authenticated user could possibly use this issue to perform a denial of service attack. This issue only affected Ubuntu 20.04 LTS. (CVE-2022-37394)

References

Affected packages

Ubuntu:Pro:16.04:LTS / nova

Package

Name
nova
Purl
pkg:deb/ubuntu/nova@2:13.1.4-0ubuntu4.5+esm1?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:13.1.4-0ubuntu4.5+esm1

Affected versions

2:12.*

2:12.0.0-0ubuntu2

2:13.*

2:13.0.0~b1-0ubuntu1
2:13.0.0~b2-0ubuntu1
2:13.0.0~b3-0ubuntu1
2:13.0.0~rc1-0ubuntu1
2:13.0.0~rc3-0ubuntu1
2:13.0.0-0ubuntu1
2:13.0.0-0ubuntu2
2:13.0.0-0ubuntu5
2:13.1.0-0ubuntu1
2:13.1.1-0ubuntu1
2:13.1.1-0ubuntu1.1
2:13.1.2-0ubuntu2
2:13.1.3-0ubuntu1
2:13.1.3-0ubuntu2
2:13.1.4-0ubuntu1
2:13.1.4-0ubuntu2
2:13.1.4-0ubuntu3
2:13.1.4-0ubuntu4.1
2:13.1.4-0ubuntu4.2
2:13.1.4-0ubuntu4.3
2:13.1.4-0ubuntu4.4
2:13.1.4-0ubuntu4.5

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "nova-api": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-volume": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-doc": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-lxc": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-console": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-novncproxy": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-libvirt": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-qemu": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-xvpvncproxy": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-api-os-compute": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-kvm": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-ajax-console-proxy": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-spiceproxy": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-vmware": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute-xen": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-network": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-conductor": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-compute": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-cert": "2:13.1.4-0ubuntu4.5+esm1",
            "python-nova": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-api-metadata": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-common": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-api-os-volume": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-scheduler": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-serialproxy": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-cells": "2:13.1.4-0ubuntu4.5+esm1",
            "nova-consoleauth": "2:13.1.4-0ubuntu4.5+esm1"
        }
    ]
}

Ubuntu:18.04:LTS / nova

Package

Name
nova
Purl
pkg:deb/ubuntu/nova@2:17.0.13-0ubuntu5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:17.0.13-0ubuntu5.3

Affected versions

2:16.*

2:16.0.1-0ubuntu1
2:16.0.1-0ubuntu2

2:17.*

2:17.0.0~b1-0ubuntu1
2:17.0.0~b2-0ubuntu2
2:17.0.0~b3-0ubuntu3
2:17.0.0~b3-0ubuntu4
2:17.0.0~rc1-0ubuntu1
2:17.0.0~rc2-0ubuntu1
2:17.0.0~rc3-0ubuntu1
2:17.0.0-0ubuntu1
2:17.0.1-0ubuntu1
2:17.0.3-0ubuntu1
2:17.0.4-0ubuntu1
2:17.0.5-0ubuntu1
2:17.0.5-0ubuntu2
2:17.0.6-0ubuntu1
2:17.0.7-0ubuntu1
2:17.0.7-0ubuntu2
2:17.0.9-0ubuntu1
2:17.0.9-0ubuntu3
2:17.0.10-0ubuntu2
2:17.0.10-0ubuntu2.1
2:17.0.11-0ubuntu1
2:17.0.12-0ubuntu1
2:17.0.13-0ubuntu1
2:17.0.13-0ubuntu2
2:17.0.13-0ubuntu3
2:17.0.13-0ubuntu4
2:17.0.13-0ubuntu5
2:17.0.13-0ubuntu5.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "nova-api": "2:17.0.13-0ubuntu5.3",
            "nova-volume": "2:17.0.13-0ubuntu5.3",
            "nova-doc": "2:17.0.13-0ubuntu5.3",
            "nova-compute-lxc": "2:17.0.13-0ubuntu5.3",
            "nova-console": "2:17.0.13-0ubuntu5.3",
            "nova-novncproxy": "2:17.0.13-0ubuntu5.3",
            "nova-compute-libvirt": "2:17.0.13-0ubuntu5.3",
            "nova-compute-qemu": "2:17.0.13-0ubuntu5.3",
            "nova-xvpvncproxy": "2:17.0.13-0ubuntu5.3",
            "nova-api-os-compute": "2:17.0.13-0ubuntu5.3",
            "nova-compute-kvm": "2:17.0.13-0ubuntu5.3",
            "nova-ajax-console-proxy": "2:17.0.13-0ubuntu5.3",
            "nova-spiceproxy": "2:17.0.13-0ubuntu5.3",
            "nova-compute-vmware": "2:17.0.13-0ubuntu5.3",
            "nova-compute-xen": "2:17.0.13-0ubuntu5.3",
            "nova-network": "2:17.0.13-0ubuntu5.3",
            "nova-conductor": "2:17.0.13-0ubuntu5.3",
            "nova-compute": "2:17.0.13-0ubuntu5.3",
            "nova-scheduler": "2:17.0.13-0ubuntu5.3",
            "python-nova": "2:17.0.13-0ubuntu5.3",
            "nova-api-metadata": "2:17.0.13-0ubuntu5.3",
            "nova-common": "2:17.0.13-0ubuntu5.3",
            "nova-api-os-volume": "2:17.0.13-0ubuntu5.3",
            "nova-placement-api": "2:17.0.13-0ubuntu5.3",
            "nova-serialproxy": "2:17.0.13-0ubuntu5.3",
            "nova-cells": "2:17.0.13-0ubuntu5.3",
            "nova-consoleauth": "2:17.0.13-0ubuntu5.3"
        }
    ]
}

Ubuntu:20.04:LTS / nova

Package

Name
nova
Purl
pkg:deb/ubuntu/nova@2:21.2.4-0ubuntu2.2?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:21.2.4-0ubuntu2.2

Affected versions

2:20.*

2:20.0.0-0ubuntu1

2:21.*

2:21.0.0~b1~git2019120415.45fb747c98-0ubuntu1
2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu2
2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu4
2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu5
2:21.0.0~b3~git2020041013.57ff308d6d-0ubuntu2
2:21.0.0-0ubuntu0.20.04.1
2:21.0.0-0ubuntu0.20.04.2
2:21.1.0-0ubuntu1
2:21.1.1-0ubuntu2
2:21.1.2-0ubuntu1
2:21.2.0-0ubuntu1
2:21.2.1-0ubuntu1
2:21.2.2-0ubuntu1
2:21.2.3-0ubuntu1
2:21.2.4-0ubuntu1
2:21.2.4-0ubuntu2
2:21.2.4-0ubuntu2.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "nova-compute-lxc": "2:21.2.4-0ubuntu2.2",
            "nova-volume": "2:21.2.4-0ubuntu2.2",
            "nova-doc": "2:21.2.4-0ubuntu2.2",
            "nova-novncproxy": "2:21.2.4-0ubuntu2.2",
            "nova-api-os-compute": "2:21.2.4-0ubuntu2.2",
            "nova-compute-kvm": "2:21.2.4-0ubuntu2.2",
            "nova-ajax-console-proxy": "2:21.2.4-0ubuntu2.2",
            "nova-spiceproxy": "2:21.2.4-0ubuntu2.2",
            "nova-compute-vmware": "2:21.2.4-0ubuntu2.2",
            "nova-compute-xen": "2:21.2.4-0ubuntu2.2",
            "nova-scheduler": "2:21.2.4-0ubuntu2.2",
            "nova-conductor": "2:21.2.4-0ubuntu2.2",
            "nova-compute": "2:21.2.4-0ubuntu2.2",
            "python3-nova": "2:21.2.4-0ubuntu2.2",
            "nova-serialproxy": "2:21.2.4-0ubuntu2.2",
            "nova-api-metadata": "2:21.2.4-0ubuntu2.2",
            "nova-compute-qemu": "2:21.2.4-0ubuntu2.2",
            "nova-api": "2:21.2.4-0ubuntu2.2",
            "nova-api-os-volume": "2:21.2.4-0ubuntu2.2",
            "nova-common": "2:21.2.4-0ubuntu2.2",
            "nova-compute-libvirt": "2:21.2.4-0ubuntu2.2",
            "nova-cells": "2:21.2.4-0ubuntu2.2"
        }
    ]
}