PT-2013-3539 · Openstack · Openstack Compute
Published
2013-07-09
·
Updated
2022-05-17
·
CVE-2013-2096
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Folsom through Havana
Description
The issue allows local users to cause a denial of service by creating an image with a large virtual size that does not contain a large amount of data, resulting in host file system disk consumption.
Recommendations
For versions Folsom through Havana, consider restricting the creation of QCOW2 images or implementing size verification to prevent excessive disk consumption until a proper fix is applied.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Compute