Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

OpenStack Nova denial of service through compressed disk images

GHSA-5644-2v3h-5w4x · CVE-2013-4463

Published · Modified

Description

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

Ready to move

Start Securing

Free, no credit card | First findings in minutes