CVE-2012-5625
published 2012-12-26CVE-2012-5625: OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.01%
79.5th percentile
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | — | — |
| openstack | folsom | — | — |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova Information leak in libvirt LVM-backed instances
osv·2022-05-17
CVE-2012-5625 [MEDIUM] OpenStack Nova Information leak in libvirt LVM-backed instances
OpenStack Nova Information leak in libvirt LVM-backed instances
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
GHSA
OpenStack Nova Information leak in libvirt LVM-backed instances
ghsa·2022-05-17
CVE-2012-5625 [MEDIUM] CWE-200 OpenStack Nova Information leak in libvirt LVM-backed instances
OpenStack Nova Information leak in libvirt LVM-backed instances
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
Red Hat
CVE-2012-5625: OpenStack Compute (Nova) Folsom before 2012
vendor_redhat·2012-12-26·CVSS 4.3
CVE-2012-5625 [MEDIUM] CWE-212 CVE-2012-5625: OpenStack Compute (Nova) Folsom before 2012
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment,
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-12-12
CVE-2012-5625 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to expose sensitive information.
Eric Windisch discovered that Nova did not properly clear LVM-backed images
before they were reallocated which could potentially lead to an information
leak. This issue only affected setups using libvirt LVM-backed instances.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-5625: nova - OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt ...
vendor_debian·2012·CVSS 4.3
CVE-2012-5625 [MEDIUM] CVE-2012-5625: nova - OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt ...
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://osvdb.org/88419http://rhn.redhat.com/errata/RHSA-2013-0208.htmlhttp://www.openwall.com/lists/oss-security/2012/12/11/5http://www.securityfocus.com/bid/56904http://www.ubuntu.com/usn/USN-1663-1https://bugs.launchpad.net/nova/+bug/1070539https://bugzilla.redhat.com/show_bug.cgi?id=884293https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5fhttps://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354https://launchpad.net/nova/folsom/2012.2.2http://osvdb.org/88419http://rhn.redhat.com/errata/RHSA-2013-0208.htmlhttp://www.openwall.com/lists/oss-security/2012/12/11/5http://www.securityfocus.com/bid/56904http://www.ubuntu.com/usn/USN-1663-1https://bugs.launchpad.net/nova/+bug/1070539https://bugzilla.redhat.com/show_bug.cgi?id=884293https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5fhttps://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354https://launchpad.net/nova/folsom/2012.2.2
2012-12-26
Published