Description
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =1:16.0.3-1 || =1:16.2.0-1 || =1:17.0.0-1 || =1:17.0.1-1 || =1:17.0.3-1 || =1:17.0.3-2 || =1:18.1.0-1 || =1:18.2.0-1 || =1:18.2.0-2 || =1:18.2.0-3 || =1:20.0.0-1 || =1:20.1.0-1 || =1:20.1.0-2 || =1:21.0.0-1 || =1:21.0.0-2 || =1:21.0.0-3 || =1:21.1.0-1 || =1:21.1.0-2 || =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 debian 12 | | =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 debian 13 | | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 debian 14 | | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || >=0 <1:35.0.1-3 | 1:35.0.1-3 |
 pypi | | | 9.1.6 |