The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4
{ "nvd_published_at": "2016-10-07T14:59:00Z", "github_reviewed_at": "2023-02-03T23:20:49Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-400" ] }