CVE-2026-24708: [OSSA-2026-002] OpenStack Nova: calls qemu-img without format strictions for size (CVE-2026-24708)

Published Jan 16, 2026
·
Updated

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with usecowimages=False) are affected.

Other sources

Unconstrained disk format handling vulnerability in OpenStack Nova when invoking the qemu-img utility. The flaw occurs because Nova does not strictly enforce the expected disk image format before calling qemu-img. An authenticated attacker can write a crafted QCOW2 header to a raw ephemeral or root disk. When Nova later performs operations such as instance resize, qemu-img interprets the disk as QCOW2 and overwrites arbitrary files on the compute host that Nova has write access to. This can be exploited without additional privileges or user interaction, allowing attackers to destroy other users’ data, corrupt Nova-managed files, or cause denial of service on the compute node.

Red Hat

Affected Software

4 affected components
Openstack Nova<30.2.2, <31.2.1, <32.1.1
pip/Nova<=30.2.1
pip/Nova>=31.0.0.0rc1<=31.2.0
pip/Nova>=32.0.0.0rc1<=32.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenStack Nova to a version that resolves this vulnerability.

    Fixed in 30.2.2
  2. Upgrade

    Upgrade OpenStack Nova to a version that resolves this vulnerability.

    Fixed in 31.2.1
  3. Upgrade

    Upgrade OpenStack Nova to a version that resolves this vulnerability.

    Fixed in 32.1.1
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch OSSA-2026-002

Event History

Jan 16, 2026
Data Sourced
via Red Hat·06:34 AM
DescriptionSeverityAffected Software
Feb 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:24 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-24708?

CVE-2026-24708 is considered a critical vulnerability due to the potential for denial of service or execution of arbitrary code.

2

How do I fix CVE-2026-24708?

To fix CVE-2026-24708, upgrade OpenStack Nova to version 30.2.2, 31.2.1, or 32.1.1 or later.

3

Who is affected by CVE-2026-24708?

CVE-2026-24708 affects all versions of OpenStack Nova prior to the specified patched versions.

4

What causes CVE-2026-24708?

CVE-2026-24708 is caused by inadequate restrictions when calling qemu-img, allowing the use of a malicious QCOW header.

5

Can CVE-2026-24708 be exploited remotely?

Yes, CVE-2026-24708 can be exploited remotely by authenticated users with access to modify snapshots.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203