First published: Wed Jun 17 2015(Updated: )
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/nova | <12.0.0.0b3 | 112.0.0.0b3 |
OpenStack Nova-LXD | >=2014.2<=2014.2.3 | |
OpenStack Nova-LXD | >=2015.1.0<=2015.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3241 has been classified as a moderate severity vulnerability that can lead to denial of service.
To fix CVE-2015-3241, upgrade to OpenStack Nova version 12.0.0.0b3 or later.
CVE-2015-3241 affects OpenStack Compute (Nova) versions 2014.2.3 and earlier, as well as versions 2015.1.0 to 2015.1.1.
CVE-2015-3241 allows remote authenticated users to cause resource consumption, leading to potential denial of service.
Yes, an authenticated remote user can exploit CVE-2015-3241 by manipulating instance migration and deletion.