Date: Thu, 16 May 2013 19:04:20 +1000 From: Michael Still <mikal@...llhq.com> To: "openstack@...ts.launchpad.net" <openstack@...ts.launchpad.net>, oss-security@...ts.openwall.com, openstack-announce@...ts.openstack.org Subject: [OSSA 2013-012] Nova fails to verify image virtual size (CVE-2013-2096) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 OpenStack Security Advisory: 2013-012 CVE: CVE-2013-2096 Date: May 16, 2013 Title: Nova fails to verify image virtual size Reporter: Loganathan Parthipan Products: Nova Affects: All versions Description: Loganathan Parthipan publicly reported a vulnerability in Nova. Nova did not implement checking for the virtual size of a qcow2 image used as ephemeral storage for instances. It is therefore possible for a user to create an image which has a large virtual size, but little data. Once the instance is created, the user can then proceed to fill the virtual disk, and consume all available disk on the host node file system. Havana (development branch) fix: https://review.openstack.org/28717 Grizzly fix: https://review.openstack.org/28901 Folsom fix: https://review.openstack.org/29192 References: https://bugs.launchpad.net/nova/+bug/1177830 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2096 Thanks, Michael Still OpenStack Vulnerability Management Team -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlGUoRQACgkQlhS32Mrx3702BgCeKZUDDA/W6Nj/xgC1a1n9vHvP vvoAnRfIOXnuvJ01c7IxGyXON7LIh5kt =YfoG -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.