PT-2026-20315 · Qemu+3 · Qemu-Img+3

Dan Smith

+1

·

Published

2026-01-01

·

Updated

2026-02-24

·

CVE-2026-24708

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Nova (affected versions not specified)
Description The software calls qemu-img without format restrictions when resizing images. A malicious QCOW header could potentially convince Nova's flat image backend to execute an unsafe image resize operation. The qemu-img function is involved in this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-24708
GHSA-M4F3-QP2W-GWH6
RHSA-2026:7884
USN-8049-1

Affected Products

Linuxmint
Openstack Nova
Ubuntu
Qemu-Img