GHSA-2w87-5qcj-j6gx

Suggest an improvement
Source
https://github.com/advisories/GHSA-2w87-5qcj-j6gx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2w87-5qcj-j6gx/GHSA-2w87-5qcj-j6gx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2w87-5qcj-j6gx
Aliases
Published
2022-05-17T04:41:34Z
Modified
2024-05-14T21:28:59.276276Z
Summary
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
Details

OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when usecowimages is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

Database specific
{
    "nvd_published_at": "2013-11-02T18:55:00Z",
    "cwe_ids": [],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-14T21:14:01Z"
}
References

Affected packages

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.0.0a0