PT-2020-14931 · Openstack+3 · Openstack Nova+3

Lee Yarwood

+1

·

Published

2020-08-26

·

Updated

2024-08-02

·

CVE-2020-17376

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Nova versions prior to 19.3.1 OpenStack Nova versions 20.x prior to 20.3.1 OpenStack Nova version 21.0.0
Description An issue was discovered in the Guest.migrate function in virt/libvirt/guest.py. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections, such as root and ephemeral devices, are affected.
Recommendations For OpenStack Nova versions prior to 19.3.1, update to version 19.3.1 or later. For OpenStack Nova versions 20.x prior to 20.3.1, update to version 20.3.1 or later. For OpenStack Nova version 21.0.0, update to a version later than 21.0.0. As a temporary workaround, consider restricting access to host devices that share the same paths as previously referenced devices to minimize the risk of exploitation.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1074
ALT-PU-2024-9720
CVE-2020-17376
GHSA-C7W7-9C85-4QXV
PYSEC-2020-243
RHSA-2020:3702
RHSA-2020:3704
RHSA-2020:3706
RHSA-2020:3708
RHSA-2020:3711
SUSE-SU-2020:2876-1
SUSE-SU-2020:2911-1
SUSE-SU-2020:3309-1
USN-5866-1

Affected Products

Alt Linux
Linuxmint
Openstack Nova
Ubuntu