First published: Tue Mar 24 2015(Updated: )
It was reported that under certain conditions (when live migrations fails), an attacker can access other VMs volumes, which under normal conditions he should not be able to access: <a href="https://bugs.launchpad.net/nova/+bug/1419577">https://bugs.launchpad.net/nova/+bug/1419577</a> CVE has been assigned here: <a href="http://seclists.org/oss-sec/2015/q1/990">http://seclists.org/oss-sec/2015/q1/990</a> No patches are available at the time of writing.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova-LXD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1205313 is considered high due to the potential unauthorized access to virtual machine volumes.
To fix REDHAT-BUG-1205313, administrators should apply the latest patches from OpenStack for the Nova component.
REDHAT-BUG-1205313 affects the OpenStack Nova versions where live migration vulnerabilities exist, primarily earlier releases.
The risks associated with REDHAT-BUG-1205313 include potential data leaks and unauthorized access to other virtual machines during migration failures.
Yes, REDHAT-BUG-1205313 can potentially be exploited remotely if an attacker has access to exploit the live migration failure scenario.