Hide Forgot
The OpenStack project reports: "" Title: Nova VMware driver still leaks rescued images Reporter: Garth Mollett (Red Hat) Products: Nova Versions: up to 2014.1.2 Description: Garth Mollett from Red Hat reported an incomplete fix to OSSA-2014-017 (CVE-2014-2573), a vulnerability affecting Nova. If an authenticated user places an instance into rescue, and then issues a suspend command it will cause the instance to enter an ERROR state. Nova does not clean up an instance in this state correctly upon deletion. An attacker can use this to launch a denial of service attack. Only setups using the Nova VMware driver are affected by this flaw. "" Acknowledgements: This issue was discovered by Garth Mollett of Red Hat Product Security.
Created attachment 942914 [details] upstream patch for juno
Created attachment 942915 [details] upstream patch for icehouse
This issue is public now: http://seclists.org/oss-sec/2014/q4/65 https://review.openstack.org/94281/ https://review.openstack.org/109624/
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1149034]
This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2014:1782 https://rhn.redhat.com/errata/RHSA-2014-1782.html
This issue has been addressed in the following products: OpenStack 5 for RHEL 6 Via RHSA-2014:1781 https://rhn.redhat.com/errata/RHSA-2014-1781.html