PT-2014-2798 · Openstack+1 · Openstack Compute+1
Bernhard M. Wiedemann
·
Published
2014-02-06
·
Updated
2023-02-13
·
CVE-2013-4463
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Folsom through Havana
Description
The issue allows local users to cause a denial of service, specifically host file system disk consumption, via a compressed QCOW2 image. This is due to the incomplete verification of the virtual size of a QCOW2 image.
Recommendations
For versions Folsom through Havana, consider restricting the use of compressed QCOW2 images until a proper fix is applied to prevent host file system disk consumption. As a temporary workaround, monitor disk usage closely to mitigate the risk of denial of service.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Compute
Ubuntu