https://seclists.org/oss-sec/2026/q2/943: [OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection bypasses Placement source claims and scheduling constraints (CVE-2026-46448)
Published Jun 16, 2026
·Updated
Affected Software
1 affected component
Openstack Nova>=18.0.0<31.3.1, >=32.0.0<32.2.1, >=33.0.0<33.0.2
Frequently Asked Questions
1
What is the severity of CVE-2026-46448?
CVE-2026-46448 is considered a critical vulnerability due to its potential to bypass scheduling constraints in OpenStack Nova.
2
How do I fix CVE-2026-46448?
To resolve CVE-2026-46448, upgrade OpenStack Nova to version 31.3.1 or later.
3
What systems are affected by CVE-2026-46448?
CVE-2026-46448 affects OpenStack Nova versions 18.0.0 to below 31.3.1.
4
What are the implications of exploiting CVE-2026-46448?
Exploiting CVE-2026-46448 allows unauthorized users to inject scheduler hints, potentially leading to misuse of resource allocation.
5
When was CVE-2026-46448 published?
CVE-2026-46448 was published on June 16, 2026.