Updated openstack-cinder and openstack-glance packages that fix one securityissue are now available for Red Hat OpenStack Platform 9.0 (Mitaka).Red Hat Product Security has rated this update as having a security impact ofModerate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
OpenStack Block Storage (cinder) manages block storage mounting and thepresentation of such mounted block storage to instances. The backend physicalstorage can consist of local disks, or Fiber Channel, iSCSI, and NFS mountsattached to Compute nodes. In addition, Block Storage supports volume backups,and snapshots for temporary save and restore operations. Programatic managementis available via Block Storage’s API.OpenStack Image service (glance) provides discovery, registration, and deliveryservices for disk and server images. It provides the ability to copy or snapshota server image, and immediately store it away. Stored images can be used as atemplate to get new servers up and running quickly and more consistently thaninstalling a server operating system and individually configuring additionalservices.Security Fix(es):* A resource vulnerability in the Block Storage (cinder) and Image (glance)services was found in their use of qemu-img. An unprivileged user could consumeas much as 4 GB of RAM on the compute host by uploading a malicious image. Thisflaw could lead possibly to host out-of-memory errors and negatively affectother running tenant instances. (CVE-2015-5162)
Red Hat OpenStack 9.0 for RHEL 7

