First published: Thu Mar 06 2014(Updated: )
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | >=2013.1<2013.1.5 | |
OpenStack Nova | >=2013.2<2013.2.2 | |
OpenStack Nova | =2014.1-milestone1 | |
pip/nova | <12.0.0a0 | 12.0.0a0 |
>=2013.1<2013.1.5 | ||
>=2013.2<2013.2.2 | ||
=2014.1-milestone1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6437 is classified as a medium severity vulnerability due to its potential for causing denial of service by consuming disk space.
To mitigate CVE-2013-6437, upgrade OpenStack Nova to version 2013.2.2 or later.
CVE-2013-6437 affects versions of OpenStack Nova prior to 2013.2.2 and specific milestone releases.
CVE-2013-6437 facilitates a denial of service attack through excessive disk consumption from instance creation and deletion.
Authenticated users can cause CVE-2013-6437 by creating and deleting instances with unique os_type settings.