Vulnerability in Nova instance resize/migration
Bug #1552683 reported by
Roman Podoliaka
This bug affects 2 people
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| Mirantis OpenStack |
Invalid
|
High
|
Sergii Rizvan | ||
| 5.1.x |
Fix Committed
|
High
|
Sergii Rizvan | ||
| 6.0.x |
Fix Committed
|
High
|
Sergii Rizvan | ||
| 6.1.x |
Fix Released
|
High
|
Sergii Rizvan | ||
| 7.0.x |
Fix Released
|
High
|
Sergii Rizvan | ||
| 8.0.x |
Invalid
|
High
|
Sergii Rizvan | ||
| 9.x |
Invalid
|
High
|
MOS Nova | ||
Bug Description
By overwriting an ephemeral or root disk with a
malicious image before requesting a resize, an authenticated user may be
able to read arbitrary files from the compute host. Only setups using
libvirt driver with raw storage and setting "use_cow_images = False"
(not default) are affected.
CVE References
| information type: | Private Security → Public Security |
| tags: | added: on-verification |
| tags: | added: covered-automated-test |
| tags: | added: feature-security |
| Changed in mos: | |
| status: | In Progress → Invalid |
To post a comment you must log in.
Please note that the patches have been updated:
https:/ /review. openstack. org/289957 (mitaka) /review. openstack. org/289958 (liberty) /review. openstack. org/289960 (kilo)
https:/
https:/