From 496d20d5fc494f5a3d45b7ce0198a0588f97210e Mon Sep 17 00:00:00 2001 From: Brian Rosmaita Date: Wed, 10 May 2023 10:49:10 -0400 Subject: [PATCH] Release glance_store for CVE-2023-2088 These releases contain a fix to the cinder glance_store driver that, when used with an appropriate os-brick release, will protect against the "accidental" case described in CVE-2023-2088. - 2023.1 (Antelope): use os-brick>=6.2.2 - Zed: use os-brick>=6.1.1 - Yoga: use os-brick>=5.2.3 Change-Id: I65929f14f1bb81e5615a69d847c0851354cb6563 Related-bug: #2004555 --- deliverables/antelope/glance-store.yaml | 4 ++++ deliverables/yoga/glance-store.yaml | 4 ++++ deliverables/zed/glance-store.yaml | 4 ++++ 3 files changed, 12 insertions(+) diff --git a/deliverables/antelope/glance-store.yaml b/deliverables/antelope/glance-store.yaml index b613a70965..8eb5dc44c6 100644 --- a/deliverables/antelope/glance-store.yaml +++ b/deliverables/antelope/glance-store.yaml @@ -15,6 +15,10 @@ releases: projects: - repo: openstack/glance_store hash: ff1f8b38ba1dd5464265ce88a8b1ad608ccef43f + - version: 4.3.1 + projects: + - repo: openstack/glance_store + hash: 884a2e459d15c5906f9a72438f248d42a8889fee branches: - name: stable/2023.1 location: 4.3.0 diff --git a/deliverables/yoga/glance-store.yaml b/deliverables/yoga/glance-store.yaml index 16adad7de4..01913108b3 100644 --- a/deliverables/yoga/glance-store.yaml +++ b/deliverables/yoga/glance-store.yaml @@ -11,6 +11,10 @@ releases: projects: - repo: openstack/glance_store hash: f3433ed1a5176bff85b3fe04dba2d4c76618a299 + - version: 3.0.1 + projects: + - repo: openstack/glance_store + hash: 7101820b6422780cbb1824335e701243491777df branches: - name: stable/yoga location: 3.0.0 diff --git a/deliverables/zed/glance-store.yaml b/deliverables/zed/glance-store.yaml index bc4c459573..ca25da8998 100644 --- a/deliverables/zed/glance-store.yaml +++ b/deliverables/zed/glance-store.yaml @@ -19,6 +19,10 @@ releases: projects: - repo: openstack/glance_store hash: ea4cdf474c166073934ff36029e54408bdd34b80 + - version: 4.1.1 + projects: + - repo: openstack/glance_store + hash: e9d2509926445fd95c9bba9e1cacacb85a5e58af branches: - name: stable/zed location: 4.1.0