Skip to content

[GHSA-3vx7-xff6-h2vx] OpenStack Nova instance migration process does not stop when instance is deleted - #9618

Open
nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9618from
nikpivkin-GHSA-3vx7-xff6-h2vx
Open

nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9618from
nikpivkin-GHSA-3vx7-xff6-h2vx

Conversation

@nikpivkin

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The first patched version should be 12.0.0.0b3, not 112.0.0.0b3. There is no nova release 112.0.0.0b3, the extra 1 looks like a typo.

The master fix linked in the advisory is openstack/nova@7ab75d5. Tag 12.0.0.0b3 contains it and tag 12.0.0.0b2 does not. The other two linked commits are the kilo and juno backports, see the reviews in https://security.openstack.org/ossa/OSSA-2015-015.html

The OSV export takes the fixed version from the first patched version, so every nova release up to the current 33.0.2 is reported as vulnerable.

Copilot AI balanced review requested due to automatic review settings September 19, 2026 12:49
@github-actions
github-actions Bot changed the base branch from main to nikpivkin/advisory-improvement-9618 September 19, 2026 12:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The corrected tag exists, contains the referenced security fix, and its preceding beta tag does not.

Review effort: Balanced
Findings: None

What changed in this PR

Corrects the OpenStack Nova advisory’s fixed version so OSV exports no longer mark later releases as vulnerable.

Changes:

  • Changes the fixed version from nonexistent 112.0.0.0b3 to verified tag 12.0.0.0b3.
  • Removes redundant affected-version metadata and updates the modification timestamp.
File Description
advisories/​github-reviewed/​2022/​05/​GHSA-3vx7-xff6-h2vx/​GHSA-3vx7-xff6-h2vx.json Corrects the Nova affected range.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants