PT-2018-6722 · Openstack+2 · Openstack Nova+2

Lee Yarwood

·

Published

2018-02-19

·

Updated

2023-02-13

·

CVE-2017-18191

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: OpenStack Nova versions 15.x through 15.1.0 OpenStack Nova versions 16.x through 16.1.1
Description: An issue in OpenStack Nova allows an attacker to access the underlying raw volume and corrupt the LUKS header by detaching and reattaching an encrypted volume. This results in a denial of service attack on the compute host. All Nova setups that support encrypted volumes are affected.
Recommendations: For OpenStack Nova versions 15.x through 15.1.0, update to a version that fixes the issue to prevent denial of service attacks. For OpenStack Nova versions 16.x through 16.1.1, update to a version that fixes the issue to prevent denial of service attacks.

Exploit

Fix

Related Identifiers

CVE-2017-18191
GHSA-FFMH-R67W-M88F
RHSA-2018:2332
RHSA-2018:2714
RHSA-2018:2855
SUSE-SU-2018:1448-1
USN-5866-1

Affected Products

Linuxmint
Openstack Nova
Ubuntu