CVEs related to bugs in Ubuntu Cloud Archive

Open bugs

Bug CVE(s)
Bug #1939733: [OSSA-2021-005] Arbitrary dnsmasq reconfiguration via extra_dhcp_opts (CVE-2021-40085) CVE-2021-40085
Ubuntu Cloud Archive New (unassigned)
Bug #1940450: XSS The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript. CVE-2019-8331
Ubuntu Cloud Archive New (unassigned)
Bug #2025319: [SRU] openvswitch 3.1.2 point release CVE-2023-1668
Ubuntu Cloud Archive Fix committed (unassigned)

Resolved bugs

Bug CVE(s)
Bug #1029430: KVM guests networking issues with no virbr0 and with vhost_net kernel modules loaded CVE-2013-0335
CVE-2013-1664
CVE-2013-1838
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1057322: Image fails to upload to swift: TypeError: object of type 'CooperativeReader' has no len( CVE-2012-4573
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1065702: After folsom upgrade, instances can no longer access existing volumes. CVE-2012-5625
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1085255: Meta bug for tracking Openstack 2012.2.1 Stable Update CVE-2012-4573
CVE-2012-5563
CVE-2012-5571
CVE-2012-5625
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1116671: Meta bug for tracking Openstack 2012.2.3 Stable Update CVE-2013-0282
CVE-2013-0335
CVE-2013-1664
CVE-2013-1665
CVE-2013-1838
CVE-2013-1840
CVE-2013-1865
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1167421: Upgrading from folsom to grizzly results in all tenants/users being disabled CVE-2013-2059
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1179626: Meta bug for tracking Openstack 2013.1.1 Stable Update CVE-2013-2059
CVE-2013-2096
Ubuntu Cloud Archive Fix released, assigned to Adam Gandelman
Bug #1179707: Meta bug for tracking OpenStack 2012.2.4 Stable Update CVE-2013-0282
CVE-2013-0335
CVE-2013-1664
CVE-2013-1838
CVE-2013-1840
CVE-2013-1865
CVE-2013-2059
CVE-2013-2096
Ubuntu Cloud Archive Fix released, assigned to Adam Gandelman
Bug #1188788: Meta bug for tracking Openstack 2013.1.2 Stable Update CVE-2013-2096
CVE-2013-2157
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1210447: Meta bug for tracking Openstack 2013.1.3 Stable Update CVE-2013-2157
CVE-2013-2256
CVE-2013-4179
CVE-2013-4183
CVE-2013-4185
CVE-2013-4202
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1262788: Meta bug for tracking Openstack 2013.2.1 Stable Update CVE-2013-4477
CVE-2013-6391
CVE-2013-6406
CVE-2013-6419
CVE-2013-6426
CVE-2013-6428
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1284643: [SRU] Meta bug for tracking Openstack 2013.2.2 CVE-2013-6437
CVE-2013-7048
CVE-2013-7130
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1374999: iSCSI volume detach does not correctly remove the multipath device descriptors CVE-2013-1068
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1387251: apparmor conflict with precise cloud archive CVE-2014-3657
CVE-2014-7823
Ubuntu Cloud Archive Fix released, assigned to Chuck Short
Bug #1403037: Need to login twice (again) CVE-2014-8124
Ubuntu Cloud Archive Fix released, assigned to James Page
Bug #1449062: [OSSA 2016-012] qemu-img calls need to be restricted by ulimit (CVE-2015-5162) CVE-2015-1850
CVE-2015-1851
CVE-2015-5162
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1493303: [OSSA 2016-004] Swift proxy memory leak on unfinished read (CVE-2016-0738) CVE-2015-5223
CVE-2016-0737
CVE-2016-0738
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1518016: [SRU] Nova kilo requires concurrency 1.8.2 or better CVE-2013-1068
Ubuntu Cloud Archive Fix released, assigned to James Page
Bug #1559215: [SRU] 2015.1.3 stable release CVE-2013-1068
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1575119: [SRU] Open vSwitch 2.4.1, 2.3.3 stable updates CVE-2016-2074
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1580334: [SRU] 2015.1.4 stable release CVE-2013-1068
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1612089: Fix for CVE-2016-5403 causes crash on migration if memory stats are enabled CVE-2016-5403
Ubuntu Cloud Archive Invalid by Corey Bryant
Bug #1641532: machine-types trusty and utopic are not unique (depend on the qemu version) CVE-2016-5403
CVE-2016-6351
CVE-2016-6490
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1664931: [OSSA-2017-005] nova rebuild ignores all image properties and scheduler filters (CVE-2017-16239) CVE-2017-16239
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1673569: [OSSA-2017-002] Failed notification payload is dumped in logs with auth secrets (CVE-2017-7214) CVE-2017-7214
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1688557: [SRU] newton stable releases CVE-2017-7214
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1706318: [SRU] magnum 4.1.3 CVE-2016-7404
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1710019: support GICv3 ITS save/restore & migration CVE-2017-1000405
CVE-2017-16995
CVE-2017-17862
CVE-2017-17863
CVE-2017-17864
CVE-2017-5754
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1723480: openvswitch-switch package postinst modifies existing configuration CVE-2017-9214
CVE-2017-9263
CVE-2017-9264
CVE-2017-9265
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1726927: [SRU] openvswitch 2.5.4 CVE-2017-9265
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1737866: Too many open files when large number of routers on a host CVE-2015-8011
CVE-2017-9214
CVE-2017-9264
CVE-2017-9265
CVE-2020-27827
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1741271: Please backport CVE-2017-13704 fix from dnsmasq 2.78 to 2.76 for Newton cloud-archive CVE-2017-13704
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1744882: Add SPEC_CTRL and IBRS changes CVE-2017-5715
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1746630: virsh api is stuck when vm is down with NFS broken CVE-2017-5715
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1748622: with last proposed libvirt/qemu update instances missing CVE-2017-5715
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1769252: [SRU] ceph 12.2.7 CVE-2018-10861
CVE-2018-1128
CVE-2018-1129
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1776509: libvirt USN-3680-1 not yet available in xenial/pike repo CVE-2018-1064
CVE-2018-3639
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1784401: [SRU] ceph 10.2.11 CVE-2018-10861
CVE-2018-1128
CVE-2018-1129
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1787599: [SRU] openvswitch 2.6.3 CVE-2017-9214
CVE-2017-9264
CVE-2017-9265
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1788103: [SRU] openvswitch 2.5.5 CVE-2017-9214
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1810766: [SRU] ceph 13.2.4 CVE-2018-14662
CVE-2018-16846
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1811098: [SRU] ceilometer writing snmp credentials to log file CVE-2019-3830
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1816468: [SRU] Acceleration cinder - glance with ceph not working CVE-2019-14433
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1820279: [FFe] [SRU] build mellon with --enable-diagnostics to ease up SSO debugging CVE-2019-3877
CVE-2019-3878
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1823200: Improper handling of ScaleIO backend credentials CVE-2020-10755
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1829380: race condition between vhost_net_stop and CHR_EVENT_CLOSED on shutdown crashes qemu (fix regression) CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-20815
CVE-2019-11091
CVE-2019-9824
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1831732: [SRU] ceph 13.2.6 CVE-2018-16889
CVE-2019-3821
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1832297: usrmerge changes path of iptables - please update libvirt on a merge of 1.8.1-x (also affects backports to undo that path change) CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2019-11091
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1833406: nova-compute-qemu package not pulling in proper qemu CVE-2019-14433
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1836713: upgrade of openvswitch packages resets alternative binaries to auto CVE-2015-8011
CVE-2020-27827
CVE-2020-35498
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1847243: Update Octavia-* packages as per OSSA-2019-005 / CVE-2019-17134 CVE-2019-17134
Ubuntu Cloud Archive Fix released, assigned to James Page
Bug #1848153: [SRU] rocky point releases CVE-2019-14433
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1848302: [SRU] queens stable releases CVE-2019-14433
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1849192: [SRU] stein stable releases CVE-2019-14433
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1850754: ceph-volume lvm list is O(n^2) CVE-2019-10222
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1850901: [SRU] ceph 14.2.4 CVE-2019-10222
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1851290: Add backport for (s390x) endian fixes to ceph nautilus CVE-2019-10222
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1853319: [SRU] stein stable releases CVE-2019-17134
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1853320: [SRU] rocky stable releases CVE-2019-17134
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1855859: [SRU] ceph 13.2.7 CVE-2019-10222
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1858304: [SRU] ceph-mgr-dashboard package missing dependencies CVE-2020-1700
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1861789: [SRU] ceph 14.2.8 CVE-2020-1699
CVE-2020-1700
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1867386: Beast frontend does not allow tuning of maximum backlog of pending connections CVE-2020-1759
CVE-2020-1760
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1878146: [SRU] ceph 14.2.9 CVE-2020-1759
CVE-2020-1760
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1879725: [SRU] Train stable releases CVE-2019-19687
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1881077: [SRU] openvswitch 2.9.7 CVE-2015-8011
CVE-2020-27827
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1883879: [SRU] ussuri stable releases CVE-2020-10755
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1883892: [SRU] train stable releases CVE-2020-10755
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1884028: [SRU] stein stable releases CVE-2020-10755
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1888198: [SRU] opevnswitch 2.5.9 CVE-2015-8011
CVE-2020-27827
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1892448: ceph 15.2.3-0ubuntu0.20.04.2 collides with ceph-deploy 2.0.1-0ubuntu1 CVE-2021-20288
CVE-2021-3509
CVE-2021-3531
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1893234: [SRU] queens stable releases CVE-2020-12689
CVE-2020-12690
CVE-2020-12691
CVE-2020-12692
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1902944: Cannot create a swift container, mandatory "Storage Policy" dropdown field is empty CVE-2020-29565
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1906280: [SRU] Add support for disabling mlockall() calls in ovs-vswitchd CVE-2015-8011
CVE-2020-27827
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1907686: ovn: instance unable to retrieve metadata CVE-2015-8011
CVE-2020-27827
CVE-2020-35498
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1912201: [SRU] openvswitch 2.9.8 CVE-2015-8011
CVE-2020-27827
CVE-2020-35498
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1912225: [SRU] openvswitch 2.11.5 CVE-2015-8011
CVE-2020-27827
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1914584: [SRU] radosgw-admin user create error message confusing if user with email already exists CVE-2021-20288
CVE-2021-3509
CVE-2021-3531
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1915787: [SRU] Train stable releases CVE-2020-29565
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1915829: FQDN / hostname recorded in OVSDB is unreliable CVE-2015-8011
CVE-2020-27827
CVE-2020-35498
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1920141: [SRU] openvswitch 2.13.3 / linking changes in DPDK 19.11.x CVE-2015-8011
CVE-2020-27827
CVE-2020-35498
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1921349: [SRU] ceph 15.2.11 CVE-2021-20288
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1923036: [SRU] Ussuri stable releases CVE-2020-29565
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1925322: [SRU] ceph 16.2.1 CVE-2021-20288
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1925347: ceph-osd fails to start with ProtectClock=true CVE-2021-20288
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1927519: Mitigate libvirt: error : unable to set AppArmor profile 'libvirt-<vm-uuid>' for '/usr/bin/kvm-spice': No such file or directory CVE-2020-10701
CVE-2020-12430
CVE-2020-14301
CVE-2020-14339
CVE-2021-3667
CVE-2021-4147
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1928645: [SRU] ceph 16.2.4 CVE-2021-3509
CVE-2021-3524
CVE-2021-3531
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1929179: [SRU] ceph 15.2.12 CVE-2021-3509
CVE-2021-3524
CVE-2021-3531
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1940959: [SRU] ceph 14.2.22 CVE-2021-20288
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1945500: [SRU] It's not possible to upload a volume that was build from an image back to glance, if multistore (glance) is enabled. CVE-2023-2088
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1956752: [SRU] openvswitch 2.15.2 CVE-2021-36980
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1956754: [SRU] openvswitch 2.13.5 CVE-2021-36980
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1960758: UEFI libvirt servers can't boot on Ubuntu 20.04 hypervisors with Ussuri/Victoria CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1978465: [SRU] Stable point releases for python-os-brick CVE-2020-10755
Ubuntu Cloud Archive Fix released (unassigned)
Bug #1980212: [SRU] openvswitch 2.16.4 CVE-2021-3905
Ubuntu Cloud Archive Invalid (unassigned)
Bug #1994002: [SRU] migration was active, but no RAM info was set CVE-2022-1050
CVE-2022-4144
CVE-2023-0330
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2011709: [SRU] zed stable releases CVE-2022-47951
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2011713: [SRU] yoga stable releases CVE-2022-47951
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2011714: [SRU] xena stable releases CVE-2022-47951
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2018564: [SRU] python-os-brick stable point releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2019460: nova-compute 23.2.2-0ubuntu1~cloud2 unable to detach volumes CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2019755: [SRU] zed stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2019759: [SRU] yoga stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2019762: [SRU] xena stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2020111: CVE-2023-2088 regressions CVE-2023-2088
Ubuntu Cloud Archive Fix released (unassigned)
Bug #2021980: Unauthorized volume access through deleted volume attachments (CVE-2023-2088) CVE-2023-2088
Ubuntu Cloud Archive Fix released (unassigned)
Bug #2025491: [SRU] antelope stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2025499: [SRU] zed stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2025503: [SRU] yoga stable releases CVE-2023-2088
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2034673: [SRU] ovn 23.03.1 point release CVE-2023-3153
Ubuntu Cloud Archive Invalid (unassigned)
Bug #2034675: [SRU] ovn 22.03.3 point release CVE-2023-3153
Ubuntu Cloud Archive Invalid (unassigned)