[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1108403: cloud-init: CVE-2024-6174



On 2025-06-30 10:40:26 +0200 (+0200), Thomas Goirand wrote:
[...]
https://review.opendev.org/c/openstack/nova/+/953732
Hopefully, this will be well received.

I however, still think the AHCI driver should be re-added in our cloud kernel though... :/

In particular because, while it may not be all that obvious, it takes a *very* long time for upstream changes in OpenStack to trickle down to deployments in the wild. There are popular public cloud providers running their service on decade-old versions of the software. This also means their users are booting the latest Debian images on relatively ancient host kernels and KVM versions, old libvirt and QEMU, et cetera.

But for this particular bug the concern is with users of non-amd64 OpenStack clouds (primarily arm64 but looks like there are also Debian genericcloud images for ppc64el), which could in theory have different drivers selected in the kernel config anyway? Or is that sort of divergence intentionally avoided between architectures?
--
Jeremy Stanley


Reply to: