CVE-2016-7498: Medium severity openstack compute (nova) vulnerability
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7498?
The severity of CVE-2016-7498 is classified as high due to its potential for causing denial of service through disk consumption.
How does CVE-2016-7498 affect OpenStack Compute (nova) 13.0.0?
CVE-2016-7498 affects OpenStack Compute (nova) 13.0.0 by allowing remote authenticated users to consume disk space by improperly deleting instances in the resize state.
What is the potential impact of CVE-2016-7498?
The potential impact of CVE-2016-7498 includes significant disk space consumption leading to denial of service for other users on the compute nodes.
How can I mitigate the risk of CVE-2016-7498?
To mitigate the risk of CVE-2016-7498, it's recommended to upgrade to a patched version of OpenStack Compute (nova) that addresses this vulnerability.
Is there a known workaround for CVE-2016-7498?
There are no specific workarounds for CVE-2016-7498 other than restricting access to the delete instance functionality while in the resize state.