Bug 1232782 (CVE-2015-3241)

Summary: CVE-2015-3241 openstack-nova: Nova instance migration process does not stop when instance is deleted
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, berrange, chrisw, dallan, dasmith, eglynn, gkotton, gmollett, jjoyce, jschluet, kbasil, kchamart, lhh, lpeer, markmc, mburns, ndipanov, nova-maint, pbrady, rbryant, sbauza, sclewis, security-response-team, sferdjao, sgordon, slinaber, slong, tdecacqu, vromanso, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in the OpenStack Compute (nova) instance migration process. Because the migration process does not terminate when an instance is deleted, an authenticated user could bypass user quota and deplete all available disk space by repeatedly re-sizing and deleting an instance.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-10-15 21:33:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1241367, 1241368, 1241369, 1241370, 1242027, 1257393, 1257789, 1257790    
Bug Blocks: 1232783    

Description Vasyl Kaigorodov 2015-06-17 13:12:05 UTC
Title: Nova instance migration process does not stop when instance is
deleted
Reporter: George Shuklin (Webzilla LTD)
Products: Nova
Affects: versions through 2014.1.4, and 2014.2 versions through
2014.2.3, and version 2015.1.0

Description:
George Shuklin from Webzilla LTD reported a vulnerability in Nova
migration process. By resizing and deleting an instance repeatedly an
authenticated user may overcome his quota and overload Nova computes
node resulting in a denial of service attack. All Nova setups are affected.

Upstream bug: https://launchpad.net/bugs/1387543

Comment 2 Garth Mollett 2015-07-09 06:38:22 UTC
Created openstack-nova tracking bugs for this issue:

Affects: fedora-all [bug 1241367]
Affects: openstack-rdo [bug 1241370]

Comment 5 Garth Mollett 2015-08-26 05:31:55 UTC
Upstream advisory:

https://security.openstack.org/ossa/OSSA-2015-015.html

Comment 6 Garth Mollett 2015-08-27 01:02:07 UTC
Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges George Shuklin of Webzilla LTD as the original reporter.

Comment 10 errata-xmlrpc 2015-09-03 17:56:08 UTC
This issue has been addressed in the following products:

  OpenStack 7 For RHEL 7

Via RHSA-2015:1723 https://access.redhat.com/errata/RHSA-2015:1723

Comment 12 errata-xmlrpc 2015-10-15 12:30:50 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 6
  OpenStack 5 for RHEL 7
  OpenStack 6 for RHEL 7

Via RHSA-2015:1898 https://rhn.redhat.com/errata/RHSA-2015-1898.html