First published: Wed Jun 17 2015(Updated: )
Title: Nova instance migration process does not stop when instance is deleted Reporter: George Shuklin (Webzilla LTD) Products: Nova Affects: versions through 2014.1.4, and 2014.2 versions through 2014.2.3, and version 2015.1.0 Description: George Shuklin from Webzilla LTD reported a vulnerability in Nova migration process. By resizing and deleting an instance repeatedly an authenticated user may overcome his quota and overload Nova computes node resulting in a denial of service attack. All Nova setups are affected. Upstream bug: <a href="https://launchpad.net/bugs/1387543">https://launchpad.net/bugs/1387543</a>
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova-LXD | <=2014.1.4>=2014.2<=2014.2.3=2015.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1232782 is considered high due to the potential for incomplete instance migration during deletion.
To fix REDHAT-BUG-1232782, upgrade to a version of OpenStack Nova that is not affected, specifically to versions after 2014.2.3 or 2015.1.1 and above.
REDHAT-BUG-1232782 affects OpenStack Nova versions up to 2014.1.4, 2014.2.x through 2014.2.3, and precisely 2015.1.0.
The impact of REDHAT-BUG-1232782 on system performance includes possible resource leaks as instance migration may continue even after an instance is deleted.
The REDHAT-BUG-1232782 vulnerability was reported by George Shuklin from Webzilla LTD.