First published: Tue Mar 01 2016(Updated: )
It was reported that by overwriting an ephemeral or root disk with a malicious image before requesting a resize, an authenticated user may be able to read arbitrary files from the compute host. Only setups using libvirt driver with raw storage and setting "use_cow_images = False" (not default) are affected. Affected versions: <=2015.1.2, >=12.0.0 <=12.0.2
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | >=12.0.0<12.0.3 | |
OpenStack Nova | >=2015.1.0<2015.1.4 | |
pip/nova | >=12.0.0<12.0.3 | 12.0.3 |
>=12.0.0<12.0.3 | ||
>=2015.1.0<2015.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.