[Openstack-security] [openstack/glance] SecurityImpact review request change Ib900bbc05cb9ccd90c6f56ccb4bf2006e30cdc80

gerrit2 at review.openstack.org gerrit2 at review.openstack.org
Fri Sep 23 17:49:28 UTC 2016


Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/375526

Log:
commit 1e804d7705a8398390c8f80ed7be2c9a6806d2c5
Author: Hemanth Makkapati <hemanth.makkapati at rackspace.com>
Date:   Fri Sep 23 09:29:12 2016 -0500

    CPU and address space limitations on qemu-img info
    
    All "qemu-img info" calls are now run under resource limitations
    that limit CPU time to 2 seconds and address space usage to 1 GB.
    This helps avoid any DoS attacks via malicious images.
    
    SecurityImpact
    
    Change-Id: Ib900bbc05cb9ccd90c6f56ccb4bf2006e30cdc80
    Closes-Bug: #1449062





More information about the Openstack-security mailing list