Bug 1154890 (CVE-2014-8333)
| Summary: | CVE-2014-8333 openstack-nova: Nova VMware instance in resize state may leak | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Murray McAllister <mmcallis> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abaron, akscram, alexander.sakhnov, aortega, apevec, apevec, ayoung, berrange, bfilippov, chrisw, dallan, dasmith, davidx, gkotton, gmollett, itamar, jonathansteffan, jose.castro.leon, lhh, lpeer, markmc, mlvov, mmagr, ndipanov, pbrady, p, rbryant, rk, sbauza, sclewis, sferdjao, sgordon, vladanovic, vromanso, yeylon |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | openstack-nova 2014.1.4 | Doc Type: | Bug Fix |
| Doc Text: |
A flaw was found in the OpenStack Compute (nova) VMWare driver, which could allow an authenticated user to delete an instance while it was in the resize state, causing the instance to remain on the back end. A malicious user could use this flaw to cause a denial of service by exhausting all available resources on the system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-06-19 07:01:15 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1154892, 1154893, 1196564, 1196565 | ||
| Bug Blocks: | 1154891, 1194087 | ||
|
Description
Murray McAllister
2014-10-21 00:56:12 UTC
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1154892] MITRE assigned CVE-2014-8333 to this issue: http://seclists.org/oss-sec/2014/q4/414 This issue has been addressed in the following products: OpenStack 5 for RHEL 6 Via RHSA-2015:0844 https://rhn.redhat.com/errata/RHSA-2015-0844.html This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2015:0843 https://rhn.redhat.com/errata/RHSA-2015-0843.html |