openstack team mailing list archive
-
openstack team
-
Mailing list archive
-
Message #23741
[OSSA 2013-012] Nova fails to verify image virtual size (CVE-2013-2096)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
OpenStack Security Advisory: 2013-012
CVE: CVE-2013-2096
Date: May 16, 2013
Title: Nova fails to verify image virtual size
Reporter: Loganathan Parthipan
Products: Nova
Affects: All versions
Description:
Loganathan Parthipan publicly reported a vulnerability in Nova. Nova
did not implement checking for the virtual size of a qcow2 image used
as ephemeral storage for instances. It is therefore possible for a
user to create an image which has a large virtual size, but little
data. Once the instance is created, the user can then proceed to fill
the virtual disk, and consume all available disk on the host node file
system.
Havana (development branch) fix:
https://review.openstack.org/28717
Grizzly fix:
https://review.openstack.org/28901
Folsom fix:
https://review.openstack.org/29192
References:
https://bugs.launchpad.net/nova/+bug/1177830
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2096
Thanks,
Michael Still
OpenStack Vulnerability Management Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iEYEARECAAYFAlGUoRQACgkQlhS32Mrx3702BgCeKZUDDA/W6Nj/xgC1a1n9vHvP
vvoAnRfIOXnuvJ01c7IxGyXON7LIh5kt
=YfoG
-----END PGP SIGNATURE-----