← Back to team overview

openstack team mailing list archive

[OSSA 2013-012] Nova fails to verify image virtual size (CVE-2013-2096)

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

OpenStack Security Advisory: 2013-012
CVE: CVE-2013-2096
Date: May 16, 2013
Title: Nova fails to verify image virtual size
Reporter: Loganathan Parthipan
Products: Nova
Affects: All versions

Description:
Loganathan Parthipan publicly reported a vulnerability in Nova. Nova
did not implement checking for the virtual size of a qcow2 image used
as ephemeral storage for instances. It is therefore possible for a
user to create an image which has a large virtual size, but little
data. Once the instance is created, the user can then proceed to fill
the virtual disk, and consume all available disk on the host node file
system.

Havana (development branch) fix:
https://review.openstack.org/28717

Grizzly fix:
https://review.openstack.org/28901

Folsom fix:
https://review.openstack.org/29192

References:
https://bugs.launchpad.net/nova/+bug/1177830
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2096

Thanks,
Michael Still
OpenStack Vulnerability Management Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlGUoRQACgkQlhS32Mrx3702BgCeKZUDDA/W6Nj/xgC1a1n9vHvP
vvoAnRfIOXnuvJ01c7IxGyXON7LIh5kt
=YfoG
-----END PGP SIGNATURE-----