openstack team mailing list archive
openstack team
Mailing list archive
Message #15566
Re: [OSSA 2012-011] Compute node filesystem injection/corruption (CVE-2012-3447)
> This might be kind-of okay if it uses libguestfs, but I'd need to look more closely at libguestfs before considering it safe. If it is only updating vfat, another option is mtools which is entirely userspace and can be run with some safety on the host.
I just realized you said glance… I'm assuming these are probably ext2/3/4 or other Linux filesystems. Libguestfs might be the best option, besides simply not having that feature.
Eric windisch
Follow ups