CVE-2024-47211
published 2024-10-04CVE-2024-47211: In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.66%
47.4th percentile
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ironic | < ironic 1:26.1.0-1 (forky) | ironic 1:26.1.0-1 (forky) |
| linux | linux_kernel | >= 0 < 4.4.0-269.303 | 4.4.0-269.303 |
| linux | linux_kernel | >= 0 < 4.15.0-238.250 | 4.15.0-238.250 |
| openstack | ironic | >= 0 < 1:26.1.0-1 | 1:26.1.0-1 |
| openstack | ironic | >= 0 < 1:26.1.0-1 | 1:26.1.0-1 |
| openstack | ironic | 0 – 21.4.3 | — |
| openstack | ironic | >= 22.0.0 < 23.0.3 | 23.0.3 |
| openstack | ironic | >= 23.1.0 < 24.1.3 | 24.1.3 |
| openstack | ironic | >= 25.0.0 < 26.1.1 | 26.1.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-azure vulnerabilities
osv·2025-06-09·CVSS 5.5
CVE-2024-56596 linux-azure vulnerabilities
linux-azure vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-56596, CVE-2024-47701, CVE-2024-26966, CVE-2021-47211,
CVE-2024-42301, CVE-2024-57850, CVE-2024-53168, CVE-2024-53155,
CVE-2024-56551)
OSV
linux-azure, linux-azure-4.15 vulnerabilities
osv·2025-06-09·CVSS 5.5
CVE-2024-57850 linux-azure, linux-azure-4.15 vulnerabilities
linux-azure, linux-azure-4.15 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-57850, CVE-2024-42301, CVE-2024-53155, CVE-2024-53168,
CVE-2024-26966, CVE-2021-47211, CVE-2024-56596, CVE-2024-56551,
CVE-2024-47701)
OSV
linux-azure-fips vulnerabilities
osv·2025-06-09·CVSS 5.5
CVE-2024-56551 linux-azure-fips vulnerabilities
linux-azure-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-56551, CVE-2024-47701, CVE-2024-57850, CVE-2024-26966,
CVE-2021-47211, CVE-2024-56596, CVE-2024-53155, CVE-2024-42301,
CVE-2024-53168)
OSV
linux-fips vulnerabilities
osv·2025-06-06·CVSS 5.5
CVE-2024-56551 linux-fips vulnerabilities
linux-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-56551, CVE-2024-53155, CVE-2024-53168, CVE-2024-42301,
CVE-2021-47211, CVE-2024-47701, CVE-2024-26966, CVE-2024-57850,
CVE-2024-56596)
OSV
linux, linux-aws, linux-kvm vulnerabilities
osv·2025-06-04·CVSS 5.5
CVE-2024-42301 linux, linux-aws, linux-kvm vulnerabilities
linux, linux-aws, linux-kvm vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Block layer subsystem;
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-42301, CVE-2024-56596, CVE-2024-56551, CVE-2023-52458,
CVE-2024-57850, CVE-2024-47701, CVE-2024-53168, CVE-2021-47211,
CVE-2024-53155, CVE-2024-26966, CVE-2021-47353)
OSV
linux-aws-fips, linux-gcp-fips vulnerabilities
osv·2025-06-04·CVSS 5.5
CVE-2024-53155 linux-aws-fips, linux-gcp-fips vulnerabilities
linux-aws-fips, linux-gcp-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-53155, CVE-2024-47701, CVE-2021-47211, CVE-2024-56596,
CVE-2024-42301, CVE-2024-57850, CVE-2024-56551, CVE-2024-26966,
CVE-2024-53168)
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
osv·2025-06-04·CVSS 5.5
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-42301, CVE-2024-53168, CVE-2024-47701, CVE-2021-47211,
CVE-2024-53155, CVE-2024-56596, CVE-2024-26966, CVE-2024-56551,
CVE-2024-57850)
OSV
linux-aws, linux-lts-xenial vulnerabilities
osv·2025-06-04·CVSS 5.5
CVE-2024-42301 linux-aws, linux-lts-xenial vulnerabilities
linux-aws, linux-lts-xenial vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Block layer subsystem;
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-42301, CVE-2024-53168, CVE-2024-57850, CVE-2024-47701,
CVE-2021-47211, CVE-2023-52458, CVE-2024-56551, CVE-2024-26966,
CVE-2024-53155, CVE-2024-56596, CVE-2021-47353)
OSV
linux-fips vulnerabilities
osv·2025-06-04·CVSS 5.5
CVE-2024-42301 linux-fips vulnerabilities
linux-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Block layer subsystem;
- Clock framework and drivers;
- GPU drivers;
- Parport drivers;
- Ext4 file system;
- JFFS2 file system;
- JFS file system;
- File systems infrastructure;
- Sun RPC protocol;
- USB sound devices;
(CVE-2024-42301, CVE-2024-26966, CVE-2023-52458, CVE-2024-47701,
CVE-2024-53155, CVE-2021-47211, CVE-2024-57850, CVE-2024-56551,
CVE-2021-47353, CVE-2024-56596, CVE-2024-53168)
OSV
OpenStack Ironic fails to verify checksums of supplied image_source URLs
osv·2024-10-04
CVE-2024-47211 [MEDIUM] OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
OSV
CVE-2024-47211: In OpenStack Ironic before 21
osv·2024-10-04·CVSS 5.3
CVE-2024-47211 [MEDIUM] CVE-2024-47211: In OpenStack Ironic before 21
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
GHSA
OpenStack Ironic fails to verify checksums of supplied image_source URLs
ghsa·2024-10-04
CVE-2024-47211 [MEDIUM] CWE-354 OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
Red Hat
openstack-ironic: Lack of checksum validation on images
vendor_redhat·2024-10-03·CVSS 5.3
CVE-2024-47211 [MEDIUM] CWE-354 openstack-ironic: Lack of checksum validation on images
openstack-ironic: Lack of checksum validation on images
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
A flaw was found in OpenStack Ironic. The lack of checksum verification allows an attacker with access to the images to modify an image without the change noticed by OpenStack. This issue leads to integrity issues in the image.
Statement: This vulnerability is classified as moderate severity rather than important because it requires a specific set of conditions for exploitation. An attacker must have access to the image source and be positioned to intercept or modify images du
Debian
CVE-2024-47211: ironic - In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x be...
vendor_debian·2024·CVSS 5.3
CVE-2024-47211 [MEDIUM] CVE-2024-47211: ironic - In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x be...
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:26.1.0-1)
sid: resolved (fixed in 1:26.1.0-1)
trixie: resolved (fixed in 1:26.1.0-1)
No detection rules found.
No public exploits indexed.
2024-10-04
Published