REDHAT-BUG-1313454: High severity openstack compute (nova) vulnerability
It was reported that by overwriting an ephemeral or root disk with a malicious image before requesting a resize, an authenticated user may be able to read arbitrary files from the compute host. Only setups using libvirt driver with raw storage and setting "usecowimages = False" (not default) are affected.
Affected versions: <=2015.1.2, >=12.0.0 <=12.0.2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1313454?
The severity of REDHAT-BUG-1313454 is considered to be significant due to the potential for unauthorized access to host files.
How do I fix REDHAT-BUG-1313454?
To mitigate REDHAT-BUG-1313454, ensure that the configuration does not allow the use of raw storage with the 'use_cow_images = False' setting.
Who is affected by REDHAT-BUG-1313454?
Users utilizing OpenStack Nova with the libvirt driver and raw storage settings are primarily affected by REDHAT-BUG-1313454.
What systems are impacted by REDHAT-BUG-1313454?
REDHAT-BUG-1313454 impacts versions of OpenStack Nova up to 2015.1.2 and between 12.0.0 to 12.0.2.
What type of exploit is associated with REDHAT-BUG-1313454?
REDHAT-BUG-1313454 allows an authenticated user to read arbitrary files from the compute host through manipulation of disk images.