REDHAT-BUG-1546937: Medium severity openstack compute (nova) vulnerability
OpenStack Nova 15.x through 15.1.0 and 16.x through 16.0.4 has a vulnerability in the handling of encrypted volumes. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host.
All Nova setups supporting encrypted volumes are affected.
Upstream Bug:
https://bugs.launchpad.net/nova/+bug/1739593
Upstream Commit:
https://review.openstack.org/#/c/539893/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1546937?
The severity of REDHAT-BUG-1546937 is considered critical due to its potential for denial of service.
How do I fix REDHAT-BUG-1546937?
To fix REDHAT-BUG-1546937, upgrade OpenStack Nova to version 15.1.1 or later, or 16.0.5 or later.
What versions of OpenStack Nova are affected by REDHAT-BUG-1546937?
OpenStack Nova versions 15.0.0 through 15.1.0 and 16.0.0 through 16.0.4 are affected by REDHAT-BUG-1546937.
What kind of attack can REDHAT-BUG-1546937 facilitate?
REDHAT-BUG-1546937 can facilitate a denial of service attack by allowing an attacker to corrupt the LUKS header of an encrypted volume.
How does REDHAT-BUG-1546937 exploit encrypted volumes?
REDHAT-BUG-1546937 exploits encrypted volumes by allowing an attacker to detach and reattach the volume, gaining access to the underlying raw volume.