PT-2018-6722 · Openstack+2 · Openstack Nova+2
Lee Yarwood
·
Published
2018-02-19
·
Updated
2023-02-13
·
CVE-2017-18191
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
OpenStack Nova versions 15.x through 15.1.0
OpenStack Nova versions 16.x through 16.1.1
Description:
An issue in OpenStack Nova allows an attacker to access the underlying raw volume and corrupt the LUKS header by detaching and reattaching an encrypted volume. This results in a denial of service attack on the compute host. All Nova setups that support encrypted volumes are affected.
Recommendations:
For OpenStack Nova versions 15.x through 15.1.0, update to a version that fixes the issue to prevent denial of service attacks.
For OpenStack Nova versions 16.x through 16.1.1, update to a version that fixes the issue to prevent denial of service attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Openstack Nova
Ubuntu