Skip to content

OpenStack Nova denial of service through compressed disk images

Low severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated May 14, 2024

Package

pip nova (pip)

Affected versions

< 12.0.0a0

Patched versions

12.0.0a0

Description

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

References

Published by the National Vulnerability Database Feb 6, 2014
Published to the GitHub Advisory Database May 17, 2022
Reviewed May 14, 2024
Last updated May 14, 2024

Severity

Low

EPSS score

0.042%
(5th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2013-4463

GHSA ID

GHSA-5644-2v3h-5w4x

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.