First published: Tue Sep 27 2016(Updated: )
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Compute (Nova) | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-7498 is classified as high due to its potential for causing denial of service through disk consumption.
CVE-2016-7498 affects OpenStack Compute (nova) 13.0.0 by allowing remote authenticated users to consume disk space by improperly deleting instances in the resize state.
The potential impact of CVE-2016-7498 includes significant disk space consumption leading to denial of service for other users on the compute nodes.
To mitigate the risk of CVE-2016-7498, it's recommended to upgrade to a patched version of OpenStack Compute (nova) that addresses this vulnerability.
There are no specific workarounds for CVE-2016-7498 other than restricting access to the delete instance functionality while in the resize state.