-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 21 Jun 2024 09:19:56 +0200 Source: cinder Binary: cinder-api cinder-backup cinder-common cinder-doc cinder-scheduler cinder-volume python3-cinder Architecture: all Version: 2:21.3.1-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-csail-02) Changed-By: Thomas Goirand Description: cinder-api - OpenStack block storage system - API server cinder-backup - OpenStack block storage system - Backup server cinder-common - OpenStack block storage system - common files cinder-doc - OpenStack block storage system - doc cinder-scheduler - OpenStack block storage system - Scheduler server cinder-volume - OpenStack block storage system - Volume server python3-cinder - OpenStack block storage system - Python libraries Closes: 1074763 Changes: cinder (2:21.3.1-1~deb12u1) bookworm-security; urgency=high . * New upstream release. * Drop CVE-2023-2088_Reject_unsafe_delete_attachment_calls.patch applied upstream. * Blacklist RBDISCSITestCase.test_unsupported_client_version(). * Add add-params-thin_provisioning-equal-one.patch. * CVE-2024-32498: Arbitrary file access through custom QCOW2 external data. Add upstream patch (Closes: #1074763): - cve-2024-32498-cinder-stable-2023.1.patch * Build-depends on qemu-utils. * Correctly calls manage_glance_api_servers() in config script. Checksums-Sha1: 081f1c6f0f20d7da4fc986c63310b50f7eb9489e 22516 cinder-api_21.3.1-1~deb12u1_all.deb 83a967cbe9b37342320def6525ea329690143230 9228 cinder-backup_21.3.1-1~deb12u1_all.deb 51aa1ea157e9641511545e7a0af1fdcc816532d8 76252 cinder-common_21.3.1-1~deb12u1_all.deb a5059146771553e9c454377f816060ccd4da1ff9 2916572 cinder-doc_21.3.1-1~deb12u1_all.deb a85713ee2d5a603d280ad56a3aa274013048609b 9572 cinder-scheduler_21.3.1-1~deb12u1_all.deb 81e6ffc2577c855cf5341937acd1ea3ac77493da 20124 cinder-volume_21.3.1-1~deb12u1_all.deb 4f67ab5611bca46e382317655ba696fd853ee893 20064 cinder_21.3.1-1~deb12u1_all-buildd.buildinfo 2c317b9383ca24757185e3304031edab753bd977 2727484 python3-cinder_21.3.1-1~deb12u1_all.deb Checksums-Sha256: 61700cc2127502d2fc798c3e339b4916ae5a06814ca98511bb538d105674cfc4 22516 cinder-api_21.3.1-1~deb12u1_all.deb de21abd6633ac72f168fdfb39e50258b2fac0ea7cd6da25ab6e82971cd51e4db 9228 cinder-backup_21.3.1-1~deb12u1_all.deb 60955efb75598d19b8055098a57e4a35201e96be884385393e7bca0fda61c8ab 76252 cinder-common_21.3.1-1~deb12u1_all.deb d62cdb276b017b9e602c96dc09bab8fcce7ab50c9be8ef9016acc3ec15fed749 2916572 cinder-doc_21.3.1-1~deb12u1_all.deb 7836b7e61de32d5b72a79c085205be5a9491fa3ee628f13dd4249edc2fc727f4 9572 cinder-scheduler_21.3.1-1~deb12u1_all.deb efcf6156ba8181c65e65224380f5be9e01104cc4bada455f67b6f6b90af587a7 20124 cinder-volume_21.3.1-1~deb12u1_all.deb 75d29c2fbacab5929ac9b49f347b7679bdbace9a1eaa3a73a88ea5d8a0c0b359 20064 cinder_21.3.1-1~deb12u1_all-buildd.buildinfo e53434253e030cb77415f3e516eaa10835ca61f8e9b23cb59b417b0a7d9f45a6 2727484 python3-cinder_21.3.1-1~deb12u1_all.deb Files: e790a041a6a2ef80b0c2852bd61008b5 22516 net optional cinder-api_21.3.1-1~deb12u1_all.deb 01578216a8d0c8b3e7e87d7e8f5d5db9 9228 net optional cinder-backup_21.3.1-1~deb12u1_all.deb 18095ca17cfe0cd0b2a622df64143cc3 76252 net optional cinder-common_21.3.1-1~deb12u1_all.deb 6e0d0b28aab6c5bf9b33930ae02584e2 2916572 doc optional cinder-doc_21.3.1-1~deb12u1_all.deb 8f882deb8601cf251fe06f443c476193 9572 net optional cinder-scheduler_21.3.1-1~deb12u1_all.deb 250adba997f765b3bf7c90e9fd7ea131 20124 net optional cinder-volume_21.3.1-1~deb12u1_all.deb f82e57fcffbb086b11c41c2dfa8b73b9 20064 net optional cinder_21.3.1-1~deb12u1_all-buildd.buildinfo 71919f9542a8eaea6d5ee868f7e32c4e 2727484 python optional python3-cinder_21.3.1-1~deb12u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzcbx6nIE/ydHa1FFigL77i1GSVkFAmbEl6gACgkQigL77i1G SVkhkg/+J2HKJDJTravfLI5DQXUC6BrECLlz40eX6J9dqy8fKAliW54KhBdMKldF O7eLSTEvlAF40ZsoIRMyOa5OkktJ8QoCXgz1L6X6tjdOppGIyqDxPAktlk3Lgw3v b1gtXUXc73bdtagx8nPseM4hLy5+K7tun+Q+el/f14xQGWhUmgjihEgCn4jEgzl3 xrjAwpNx00j6CH8uAyR5x2QeB8FTn3QHbJXo+bfZc2y4Rf6X4MrthE1Lg/cD3JmV sA8S3mbvtBH/PO3ZOy1II5kFf0yz4hKGe9MON4q7xrXsTg3Cmf2JELgIxjABlBJ/ 4RdfPEchmac70CSNFUw2jGqLd9fFI8Azp44Dbyn8jysGsHcI1unDHAb+9LAHSL1U bKeBy6ifhwJo6Znz99R0jfqLRJ37NY8+qg2u0XByPiYsQcNf36PpREo2HgVeBHi6 aaGpxpuiTNSCwhr5Xu2Kgu8hRJjRwmI1Wks9BLvOlwn5WR5CPt4QxDpNqDuyWp5E gvb2CyhKFwFc/Sot9jrBS8lzLLJAey5ya8QD2Sf8Ukp83hfx0bG0dfh9ZXHB7w8S tcU+foMsRSEGGlKI3kkkr8c7Zet9OcivllofWNwdgwvTw2lr4MZRrpZiUWp/07t3 lZNN4q2pu/vRzaq5rEbNO+whaVuLWggfRPIvWQo+n6oveTXNOQg= =Kx3v -----END PGP SIGNATURE-----