Bug 836658 (CVE-2012-3371)

Summary: CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: apevec, jrusnack, kseifried, markmc, pbrady, rbryant, rkukura, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-09-12 19:07:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 839407, 844041    
Bug Blocks:    
Attachments:
Description Flags
Upstream patch for Essex
none
Upstream patch for Folsom none

Description Kurt Seifried 2012-06-29 20:41:06 UTC
Title: Scheduler denial of service through scheduler_hints
Impact: Medium
Reporter: Dan Prince (Red Hat)
Products: Nova
Affects: Essex, Folsom series

Description:
Dan Prince from Red Hat reported a vulnerability in Nova scheduler
nodes. By creating servers with malicious scheduler_hints, an
authenticated user may generate a huge amount of database calls,
potentially resulting in a Denial of Service attack against Nova
scheduler nodes. Only setups exposing the OpenStack API and enabling
DifferentHostFilter and/or SameHostFilter are affected.

Comment 3 Tomas Hoger 2012-07-04 07:44:53 UTC
Created attachment 596162 [details]
Upstream patch for Essex

Comment 4 Tomas Hoger 2012-07-04 07:45:38 UTC
Created attachment 596163 [details]
Upstream patch for Folsom

Comment 5 Kurt Seifried 2012-07-11 21:32:32 UTC
Created openstack-nova tracking bugs for this issue

Affects: fedora-all [bug 839407]

Comment 7 Kurt Seifried 2012-07-28 06:20:33 UTC
Created openstack-nova tracking bugs for this issue

Affects: epel-6 [bug 844041]