The OpenStack project reports: "" Title: Nova VMware instance in resize state may leak Reporter: Zhu Zhu (IBM) Products: Nova Versions: up to 2014.1.3 Description: Zhu Zhu from IBM reported a vulnerability in Nova VMware driver. If an authenticated user deletes an instance while it is in resize state, it will cause the original instance to not be deleted. An attacker can use this to launch a denial of service attack. All Nova VMware setups are affected. "" CVE request: http://seclists.org/oss-sec/2014/q4/408 References: https://launchpad.net/bugs/1359138 https://git.openstack.org/cgit/openstack/nova/commit/?id=d71445c7d2d2921d10a08f82330f0ab8ef4f7df2
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1154892]
MITRE assigned CVE-2014-8333 to this issue: http://seclists.org/oss-sec/2014/q4/414
This issue has been addressed in the following products: OpenStack 5 for RHEL 6 Via RHSA-2015:0844 https://rhn.redhat.com/errata/RHSA-2015-0844.html
This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2015:0843 https://rhn.redhat.com/errata/RHSA-2015-0843.html