|
|
Log in / Subscribe / Register

openstack-nova: information exposure

Package(s):openstack-nova CVE #(s):CVE-2016-2140
Created:March 9, 2016 Updated:March 9, 2016
Description: From the Red Hat advisory:

An information-exposure flaw was found in the OpenStack Compute (nova) resize and migrate functionality. An authenticated user could write a malicious qcow header to an ephemeral or root disk, referencing a block device as a backing file. With a subsequent resize or migration, file system content on the specified device would be leaked to the user. Only setups using libvirt with raw storage and "use_cow_images = False" were affected.

Alerts:
Red Hat RHSA-2016:0366-01 openstack-nova 2016-03-08
Red Hat RHSA-2016:0365-01 openstack-nova 2016-03-08
Red Hat RHSA-2016:0364-01 openstack-nova 2016-03-08
Red Hat RHSA-2016:0363-01 openstack-nova 2016-03-08

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds