Vulnerability in Nova instance resize/migration
Bug #1552683 reported by
Roman Podoliaka
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mirantis OpenStack |
Invalid
|
High
|
Sergii Rizvan | ||
5.1.x |
Fix Committed
|
High
|
Sergii Rizvan | ||
6.0.x |
Fix Committed
|
High
|
Sergii Rizvan | ||
6.1.x |
Fix Released
|
High
|
Sergii Rizvan | ||
7.0.x |
Fix Released
|
High
|
Sergii Rizvan | ||
8.0.x |
Invalid
|
High
|
Sergii Rizvan | ||
9.x |
Invalid
|
High
|
MOS Nova |
Bug Description
By overwriting an ephemeral or root disk with a
malicious image before requesting a resize, an authenticated user may be
able to read arbitrary files from the compute host. Only setups using
libvirt driver with raw storage and setting "use_cow_images = False"
(not default) are affected.
CVE References
information type: | Private Security → Public Security |
tags: | added: on-verification |
tags: | added: covered-automated-test |
tags: | added: feature-security |
Changed in mos: | |
status: | In Progress → Invalid |
To post a comment you must log in.
Please note that the patches have been updated:
https:/ /review. openstack. org/289957 (mitaka) /review. openstack. org/289958 (liberty) /review. openstack. org/289960 (kilo)
https:/
https:/