watcher (14.0.0-3)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/openstack-team/services/watcher.git
-
- Branch: debian/flamingo
- Path: debian/changelog
- Repo size: 3596288
- Browser: https://salsa.debian.org/openstack-team/services/watcher
- Last scan: 2025-09-07 05:33:04+00
- Next scan: 2025-09-15 13:37:00+00
- CI pipeline status: failed
- Debian changelog in Git:
watcher (14.0.0-3) unstable; urgency=high
* A vulnerability has been identified in OpenStack Nova and OpenStack Watcher
in conjunction with volume swap operations performed by the Watcher
service. Under specific circumstances, this can lead to a situation where
two Nova libvirt instances could reference the same block device, allowing
accidental information disclosure to the unauthorized instance. Added
upstream patch: OSSN-0094_use_cinder_migrate_for_swap_volume.patch.
(Closes: #1111692).
-- Thomas Goirand <zigo@debian.org> Thu, 21 Aug 2025 10:27:37 +0200
- This branch is even with tag debian/14.0.0-3