CVE-2012-3371
published 2012-07-17CVE-2012-3371: The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.85%
76.7th percentile
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1.1-5 (bookworm) | nova 2012.1.1-5 (bookworm) |
| openstack | compute | — | — |
| openstack | essex | — | — |
| openstack | folsom | — | — |
| openstack | nova | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | nova | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | nova | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | nova | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-07-11
CVE-2012-3371 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to not respond if passed specially crafted input.
Dan Prince discovered that the Nova scheduler, when using
DifferentHostFilter or SameHostFilter, would make repeated database
instance lookup calls based on passed scheduler hints. An authenticated
attacker could use this to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-3371: nova - The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1...
vendor_debian·2012·CVSS 3.5
CVE-2012-3371 [LOW] CVE-2012-3371: nova - The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1...
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
Scope: local
bookworm: resolved (fixed in 2012.1.1-5)
bullseye: resolved (fixed in 2012.1.1-5)
forky: resolved (fixed in 2012.1.1-5)
sid: resolved (fixed in 2012.1.1-5)
trixie: resolved (fixed in 2012.1.1-5)
OSV
OpenStack Nova Scheduler denial of service through scheduler_hints
osv·2022-05-17
CVE-2012-3371 [LOW] OpenStack Nova Scheduler denial of service through scheduler_hints
OpenStack Nova Scheduler denial of service through scheduler_hints
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
GHSA
OpenStack Nova Scheduler denial of service through scheduler_hints
ghsa·2022-05-17
CVE-2012-3371 [LOW] CWE-20 OpenStack Nova Scheduler denial of service through scheduler_hints
OpenStack Nova Scheduler denial of service through scheduler_hints
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
OSV
CVE-2012-3371: The Nova scheduler in OpenStack Compute (Nova) Folsom (2012
osv·2012-07-17·CVSS 3.5
CVE-2012-3371 [LOW] CVE-2012-3371: The Nova scheduler in OpenStack Compute (Nova) Folsom (2012
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [epel-6]
bugzilla·2012-07-28·CVSS 3.5
CVE-2012-3371 [LOW] CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [epel-6]
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/
Bugzilla
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [fedora-all]
bugzilla·2012-07-11·CVSS 3.5
CVE-2012-3371 [LOW] CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [fedora-all]
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/
Bugzilla
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints
bugzilla·2012-06-29·CVSS 3.5
CVE-2012-3371 [LOW] CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints
CVE-2012-3371 OpenStack-Nova: Scheduler denial of service through scheduler_hints
Title: Scheduler denial of service through scheduler_hints
Impact: Medium
Reporter: Dan Prince (Red Hat)
Products: Nova
Affects: Essex, Folsom series
Description:
Dan Prince from Red Hat reported a vulnerability in Nova scheduler
nodes. By creating servers with malicious scheduler_hints, an
authenticated user may generate a huge amount of database calls,
potentially resulting in a Denial of Service attack against Nova
scheduler nodes. Only setups exposing the OpenStack API and enabling
DifferentHostFilter and/or SameHostFilter are affected.
Discussion:
Created attachment 596162
Upstream patch for Essex
---
Created attachment 596163
Upstream patch for Folsom
---
Created openstack-nova tracking bugs for
http://www.openwall.com/lists/oss-security/2012/07/11/13http://www.securityfocus.com/bid/54388http://www.ubuntu.com/usn/USN-1501-1https://bugs.launchpad.net/nova/+bug/1017795https://github.com/openstack/nova/commit/034762e8060dcf0a11cb039b9d426b0d0bb1801dhttps://lists.launchpad.net/openstack/msg14452.htmlhttp://www.openwall.com/lists/oss-security/2012/07/11/13http://www.securityfocus.com/bid/54388http://www.ubuntu.com/usn/USN-1501-1https://bugs.launchpad.net/nova/+bug/1017795https://github.com/openstack/nova/commit/034762e8060dcf0a11cb039b9d426b0d0bb1801dhttps://lists.launchpad.net/openstack/msg14452.html
2012-07-17
Published