Title: Nova instance migration process does not stop when instance is deleted Reporter: George Shuklin (Webzilla LTD) Products: Nova Affects: versions through 2014.1.4, and 2014.2 versions through 2014.2.3, and version 2015.1.0 Description: George Shuklin from Webzilla LTD reported a vulnerability in Nova migration process. By resizing and deleting an instance repeatedly an authenticated user may overcome his quota and overload Nova computes node resulting in a denial of service attack. All Nova setups are affected. Upstream bug: https://launchpad.net/bugs/1387543
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1241367] Affects: openstack-rdo [bug 1241370]
Upstream advisory: https://security.openstack.org/ossa/OSSA-2015-015.html
Acknowledgements: Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges George Shuklin of Webzilla LTD as the original reporter.
This issue has been addressed in the following products: OpenStack 7 For RHEL 7 Via RHSA-2015:1723 https://access.redhat.com/errata/RHSA-2015:1723
This issue has been addressed in the following products: OpenStack 5 for RHEL 6 OpenStack 5 for RHEL 7 OpenStack 6 for RHEL 7 Via RHSA-2015:1898 https://rhn.redhat.com/errata/RHSA-2015-1898.html