PT-2014-2798 · Openstack+1 · Openstack Compute+1

Bernhard M. Wiedemann

·

Published

2014-02-06

·

Updated

2023-02-13

·

CVE-2013-4463

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions Folsom through Havana
Description The issue allows local users to cause a denial of service, specifically host file system disk consumption, via a compressed QCOW2 image. This is due to the incomplete verification of the virtual size of a QCOW2 image.
Recommendations For versions Folsom through Havana, consider restricting the use of compressed QCOW2 images until a proper fix is applied to prevent host file system disk consumption. As a temporary workaround, monitor disk usage closely to mitigate the risk of denial of service.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2013-4463
GHSA-5644-2V3H-5W4X
RHSA-2014:0112
USN-2247-1

Affected Products

Openstack Compute
Ubuntu