Skip to content

OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image

Low severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated May 14, 2024

Package

pip nova (pip)

Affected versions

< 12.0.0a0

Patched versions

12.0.0a0

Description

OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

References

Published by the National Vulnerability Database Nov 2, 2013
Published to the GitHub Advisory Database May 17, 2022
Reviewed May 14, 2024
Last updated May 14, 2024

Severity

Low

Weaknesses

No CWEs

CVE ID

CVE-2013-4469

GHSA ID

GHSA-2w87-5qcj-j6gx

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.