First published: Wed Dec 05 2012(Updated: )
Thierry Carrez (thierry) has released information Title: Information leak in libvirt LVM-backed instances Reporter: Eric Windisch (Cloudscaling) Products: Nova Affects: Folsom, Grizzly Description: Eric Windisch from Cloudscaling reported a vulnerability in libvirt LVM-backed instances. The physical volume content was not wiped out before being reallocated and passed to an instance, which may result in the disclosure of information from previously-allocated logical volumes. Only setups using libvirt and LVM-backed instances (libvirt_images_type=lvm) are affected. This was originally reported by Eric Windisch from Cloudscaling
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova-LXD | >=Folsom<=Grizzly |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-884293 is classified as an information leak vulnerability.
To fix REDHAT-BUG-884293, upgrade to a version of OpenStack Nova beyond Grizzly.
REDHAT-BUG-884293 affects OpenStack Nova versions from Folsom to Grizzly.
REDHAT-BUG-884293 primarily involves libvirt and LVM-backed instances in OpenStack.
The vulnerability related to REDHAT-BUG-884293 was reported by Eric Windisch from Cloudscaling.