Bug 1043106 (CVE-2013-6437) - CVE-2013-6437 openstack-nova: DoS through ephemeral disk backing files
Summary: CVE-2013-6437 openstack-nova: DoS through ephemeral disk backing files
Status: CLOSED ERRATA
Alias: CVE-2013-6437
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20131218,repor...
Keywords: Security
Depends On: 1119586 1063638 1119584 1119585
Blocks: 1023240 1043107
TreeView+ depends on / blocked
 
Reported: 2013-12-13 23:23 UTC by Vincent Danen
Modified: 2016-04-26 18:30 UTC (History)
14 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2014-07-15 06:18:50 UTC


Attachments (Terms of Use)
grizzly patch (4.98 KB, patch)
2013-12-13 23:31 UTC, Vincent Danen
no flags Details | Diff
havana patch (5.07 KB, patch)
2013-12-13 23:33 UTC, Vincent Danen
no flags Details | Diff
icehouse patch (4.94 KB, patch)
2013-12-13 23:34 UTC, Vincent Danen
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0231 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix update 2014-03-05 00:00:29 UTC

Description Vincent Danen 2013-12-13 23:23:27 UTC
Thierry Carrez of the OpenStack project reports:


Title: Nova compute DoS through ephemeral disk backing files
Reporter: Phil Day (HP)
Products: Nova
Affects: All supported versions

Description:
Phil Day from HP reported a vulnerability in the libvirt driver handling
of ephemeral disk backing files on Nova compute nodes. By repeatedly
creating snapshots, changing the os_type to a new random value, and
spawning new instances from the snapshot (and quickly deleting those
instances), an authenticated user could generate lots of different
ephemeral disk backing files and fill up compute node disks, potentially
resulting in a Denial of Service against a Nova setup. Only Nova setups
running the libvirt driver are affected.


CVE-2013-6437 has been assigned to identify this flaw.


Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Phil Day from HP as the original reporter.

Comment 2 Vincent Danen 2013-12-13 23:31:17 UTC
Created attachment 836520 [details]
grizzly patch

Comment 3 Vincent Danen 2013-12-13 23:33:25 UTC
Created attachment 836521 [details]
havana patch

Comment 4 Vincent Danen 2013-12-13 23:34:19 UTC
Created attachment 836523 [details]
icehouse patch

Comment 6 errata-xmlrpc 2014-03-04 19:04:35 UTC
This issue has been addressed in following products:

  OpenStack 4 for RHEL 6

Via RHSA-2014:0231 https://rhn.redhat.com/errata/RHSA-2014-0231.html

Comment 7 Garth Mollett 2014-07-15 06:11:12 UTC
Trackers were never added for fedora/rdo when this was unembargoed. It's almost certainly been fixed in a rebase since then but filing anyway.

Comment 8 Garth Mollett 2014-07-15 06:16:36 UTC
Statement:

Red Hat Product Security has rated this issue as having moderate security impact in Red Hat OpenStack Platform 3.0. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 10 Garth Mollett 2014-07-15 06:18:02 UTC
Created openstack-nova tracking bugs for this issue:

Affects: fedora-all [bug 1119584]
Affects: epel-6 [bug 1119585]


Note You need to log in before you can comment on or make changes to this bug.