PT-2016-3669 · Openstack+2 · Openstack Nova+4

Richard W.M. Jones

·

Published

2016-10-07

·

Updated

2023-02-13

·

CVE-2015-5162

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenStack Cinder versions 7.0.0 through 7.0.1 and 8.0.0 through 8.1.1 and prior to 9.0.0 OpenStack Glance versions prior to 11.0.1 and 12.0.0 and prior to 14.0.0 OpenStack Nova versions prior to 12.0.4 and 13.0.0
Description The image parser in OpenStack does not properly limit qemu-img calls, which might allow attackers to cause a denial of service via a crafted disk image, leading to memory and disk consumption.
Recommendations For OpenStack Cinder versions 7.0.0 through 7.0.1, update to version 7.0.2 or 9.0.0. For OpenStack Cinder versions 8.0.0 through 8.1.1, update to version 9.0.0. For OpenStack Glance versions prior to 11.0.1, update to version 11.0.1 or 14.0.0. For OpenStack Glance versions 12.0.0 but prior to 14.0.0, update to version 14.0.0. For OpenStack Nova versions prior to 12.0.4, update to version 12.0.4. For OpenStack Nova versions 13.0.0, no specific fix is mentioned, consider updating to a newer version if available.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2015-5162
GHSA-G2J5-7VGX-6XRX
RHSA-2016:2923
RHSA-2016:2991
RHSA-2017:0153
RHSA-2017:0156
RHSA-2017:0165
RHSA-2017:0282
USN-3449-1

Affected Products

Openstack Cinder
Openstack Glance
Openstack Nova
Ubuntu
Qemu-Img