cloud-init 23.1.2-0ubuntu0~22.10.1 source package in Ubuntu

Changelog

cloud-init (23.1.2-0ubuntu0~22.10.1) kinetic; urgency=medium

  * SECURITY UPDATE: Make user/vendor data sensitive and remove log permissions
    Because user data and vendor data may contain sensitive information,
    this commit ensures that any user data or vendor data written to
    instance-data.json gets redacted and is only available to root user.

    Also, modify the permissions of cloud-init.log to be 640, so that
    sensitive data leaked to the log isn't world readable.
    Additionally, remove the logging of user data and vendor data to
    cloud-init.log from the Vultr datasource.

    This is based on upstream snapshot of 23.1.2 [(LP: #2013967)]

    - d/cloud-init.postinst: postinst fixes for LP: #2013967
      Redact sensitive keys from world-readable instance-data.json on upgrade.
      Set perms 640 for /var/log/cloud-init.log on pkg upgrade.
      Redact sensitive Vultr messages from /var/log/cloud-init.log
    - (CVE-2023-1786)

 -- James Falcon <email address hidden>  Fri, 21 Apr 2023 14:21:43 -0500

Upload details

Uploaded by:
James Falcon
Sponsored by:
Chad Smith
Uploaded to:
Kinetic
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
admin
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Kinetic: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
cloud-init_23.1.2.orig.tar.gz 1.5 MiB 4c3a2499d9953902a550e2134cceb5a9afd2324009404f6d52bb82d3e96dec3f
cloud-init_23.1.2-0ubuntu0~22.10.1.debian.tar.xz 87.3 KiB eee38b87f768bb44b13713b352541ee8594ad40bd842f662bd134b68ea263dd3
cloud-init_23.1.2-0ubuntu0~22.10.1.dsc 2.2 KiB d576c8c0b0b5b249758bda7e6898a1c8e5d67e7e7ef0e8671a33fd84e876be33

View changes file

Binary packages built by this source

cloud-init: No summary available for cloud-init in ubuntu kinetic.

No description available for cloud-init in ubuntu kinetic.