Bug 2489379 (CVE-2026-46448) - CVE-2026-46448 openstack-nova: OpenStack Nova: Resource allocation issue due to unstripped hint data in server creation API
Summary: CVE-2026-46448 openstack-nova: OpenStack Nova: Resource allocation issue due ...
Keywords:
Status: NEW
Alias: CVE-2026-46448
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-16 20:01 UTC by OSIDB Bzimport
Modified: 2026-07-30 10:11 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-16 20:01:58 UTC
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Comment 3 Christopher Lusk 2026-07-17 15:36:39 UTC
CVSS re-evaluation: RH score updated from 6.5 (Moderate) to 8.5 (Important) to align with NIST.

The original RH vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H = 6.5) was auto-populated by AEGIS with no manual analysis. Lucas Celant flagged a 2.0-point discrepancy crossing the Medium/High severity boundary against NIST's score (AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H = 8.5).

Two metrics were re-evaluated:

- Scope (S:U → S:C): The scheduler hint injection bypasses Placement and scheduling constraints, allowing a tenant to affect co-located tenants' resource availability and potentially escape AZ/host aggregate isolation. This crosses the tenant security boundary, justifying Changed scope.

- Integrity (I:N → I:L): The missing Placement allocations cause the resource accounting state in the Placement service to no longer reflect reality. Instances exist on compute nodes but are untracked, corrupting the integrity of the resource management subsystem.

Updated vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H = 8.5 (Important).


Note You need to log in before you can comment on or make changes to this bug.