openstack-nova: information exposure
| Package(s): | openstack-nova |
CVE #(s): | CVE-2016-2140
|
| Created: | March 9, 2016 |
Updated: | March 9, 2016 |
| Description: |
From the Red Hat advisory:
An information-exposure flaw was found in the OpenStack Compute (nova)
resize and migrate functionality. An authenticated user could write a
malicious qcow header to an ephemeral or root disk, referencing a block
device as a backing file. With a subsequent resize or migration, file
system content on the specified device would be leaked to the user. Only
setups using libvirt with raw storage and "use_cow_images = False" were
affected. |
| Alerts: |
|