CVE-2015-5162
published 2016-10-07CVE-2015-5162: The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.06%
86.2th percentile
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2:8.0.0-1 (bookworm) | cinder 2:8.0.0-1 (bookworm) |
| debian | glance | < cinder 2:8.0.0-1 (bookworm) | cinder 2:8.0.0-1 (bookworm) |
| debian | nova | < cinder 2:8.0.0-1 (bookworm) | cinder 2:8.0.0-1 (bookworm) |
| glance_project | glance | >= 0 < 2:12.0.0-1 | 2:12.0.0-1 |
| glance_project | glance | >= 0 < 2:12.0.0-1 | 2:12.0.0-1 |
| glance_project | glance | >= 0 < 2:12.0.0-1 | 2:12.0.0-1 |
| glance_project | glance | >= 0 < 2:12.0.0-1 | 2:12.0.0-1 |
| glance_project | glance | >= 0 < 14.0.0 | 14.0.0 |
| openstack | cinder | — | — |
| openstack | cinder | — | — |
| openstack | cinder | — | — |
| openstack | cinder | >= 0 < 2:8.0.0-1 | 2:8.0.0-1 |
| openstack | cinder | >= 0 < 2:8.0.0-1 | 2:8.0.0-1 |
| openstack | cinder | >= 0 < 2:8.0.0-1 | 2:8.0.0-1 |
| openstack | cinder | >= 0 < 2:8.0.0-1 | 2:8.0.0-1 |
| openstack | cinder | >= 0 < 7.0.2 | 7.0.2 |
| openstack | cinder | >= 8.0.0 < 9.0.0 | 9.0.0 |
| openstack | glance | <= 11.0.0 | — |
| openstack | glance | — | — |
| openstack | glance | — | — |
| openstack | nova | <= 12.0.3 | — |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.8
CVE-2015-3241 [MEDIUM] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: Several security issues were fixed in OpenStack Nova.
George Shuklin discovered that OpenStack Nova incorrectly handled the
migration process. A remote authenticated user could use this issue to
consume resources, resulting in a denial of service. (CVE-2015-3241)
George Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly
handled deleting instances. A remote authenticated user could use this
issue to consume disk resources, resulting in a denial of service.
(CVE-2015-3280)
It was discovered that OpenStack Nova incorrectly limited qemu-img calls. A
remote authenticated user could use this issue to consume resources,
resulting in a denial of service. (CVE-2015-5162)
Matthew Booth discovered that OpenStack Nova incorrectly han
Red Hat
openstack-nova/glance/cinder: Malicious image may exhaust resources
vendor_redhat·2015-06-29·CVSS 7.5
CVE-2015-5162 [HIGH] CWE-400 openstack-nova/glance/cinder: Malicious image may exhaust resources
openstack-nova/glance/cinder: Malicious image may exhaust resources
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
A resource vulnerability in the OpenStack Compute (nova), Block Storage (cinder), and Image (glance) services was found in their use of qemu-img. An unprivileged user could consume as much as 4 GB of RAM on the compute host by uploading a malicious image. This flaw could lead possibly to host out-of-memory errors and negatively affect other running tenant instances.
oslo.concurrency has been updated to support process limits ('prlimit'),
Debian
CVE-2015-5162: cinder - The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance befor...
vendor_debian·2015·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162: cinder - The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance befor...
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
Scope: local
bookworm: resolved (fixed in 2:8.0.0-1)
bullseye: resolved (fixed in 2:8.0.0-1)
forky: resolved (fixed in 2:8.0.0-1)
sid: resolved (fixed in 2:8.0.0-1)
trixie: resolved (fixed in 2:8.0.0-1)
OSV
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
osv·2022-05-14
CVE-2015-5162 [HIGH] OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4
GHSA
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
ghsa·2022-05-14
CVE-2015-5162 [HIGH] CWE-400 OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4
OSV
nova vulnerabilities
osv·2017-10-11·CVSS 6.8
CVE-2015-3241 [MEDIUM] nova vulnerabilities
nova vulnerabilities
George Shuklin discovered that OpenStack Nova incorrectly handled the
migration process. A remote authenticated user could use this issue to
consume resources, resulting in a denial of service. (CVE-2015-3241)
George Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly
handled deleting instances. A remote authenticated user could use this
issue to consume disk resources, resulting in a denial of service.
(CVE-2015-3280)
It was discovered that OpenStack Nova incorrectly limited qemu-img calls. A
remote authenticated user could use this issue to consume resources,
resulting in a denial of service. (CVE-2015-5162)
Matthew Booth discovered that OpenStack Nova incorrectly handled snapshots.
A remote authenticated user could use this issue to read arbitrar
OSV
CVE-2015-5162: The image parser in OpenStack Cinder 7
osv·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162: The image parser in OpenStack Cinder 7
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-10908 [HIGH] CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
A vulnerability was found in ovirt, allowing a user to consume large amounts of memory or CPU time on the host by uploading a maliciously crafted image. This could lead to denial of service on the host, potentially impacting other users.
Discussion:
See also CVE-2015-5162, essentially the same issue on Openstack.
---
Discussion:
http://lists.nongnu.org/archive/html/qemu-block/2018-07/msg00488.html
---
Statement:
Red Hat Enterprise Virtualization 3 is now in Extended Life Phase of the support and maintenance lifecycle. Red Hat Product Security has rated this issue as having a security impact of Moderate, and it is not currently planned to be addressed in future updates of Red Hat Virtualization 3. For additi
Bugzilla
CVE-2015-5162 openstack-nova: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-nova: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
CVE-2015-5162 openstack-nova: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2015-5162 openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
CVE-2015-5162 openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
This as an RDO Project security tracking bug against openstack-nova. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Closing ERRATA as upstream tracking bug has been done the same.
Bugzilla
CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [fedora-all]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [fedora-all]
CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
CVE-2015-5162 openstack-cinder: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
This as an RDO Project security tracking bug against openstack-cinder. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Closing ERRATA as upstream tracking bug has been done the same.
Bugzilla
CVE-2015-5162 openstack-glance: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-glance: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
CVE-2015-5162 openstack-glance: openstack-nova/glance/cinder: Malicious image may exhaust resources [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2015-5162 openstack-glance: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
bugzilla·2016-10-07·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-glance: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
CVE-2015-5162 openstack-glance: openstack-nova: Malicious image causes OOM on the compute host [openstack-rdo]
This as an RDO Project security tracking bug against openstack-glance. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Closing ERRATA as upstream tracking bug has been done the same.
Bugzilla
CVE-2015-5162 openstack-nova/glance/cinder: Malicious image may exhaust resources
bugzilla·2015-10-02·CVSS 7.5
CVE-2015-5162 [HIGH] CVE-2015-5162 openstack-nova/glance/cinder: Malicious image may exhaust resources
CVE-2015-5162 openstack-nova/glance/cinder: Malicious image may exhaust resources
A vulnerability in openstack-nova was found, allowing an unprivileged user to consume as much as 4 GB of RAM on the host by uploading malicoius image, possibly leading to OOM on the compute host, negatively affecting the other running instances for other tenants.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1267576
Upstream bug:
https://bugs.launchpad.net/ossa/+bug/1449062
Discussion:
Upstream patches have been released:
- https://review.openstack.org/382573 (cinder) (Liberty)
- https://review.openstack.org/378012 (glance) (Liberty)
- https://review.openstack.org/327624 (nova) (Liberty)
- https://review.openstack.org/375625 (cinder) (Mitaka)
- https://review.openstack.org/377736 (glance) (M
http://rhn.redhat.com/errata/RHSA-2016-2923.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2991.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0153.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0156.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0282.htmlhttp://www.openwall.com/lists/oss-security/2016/10/06/8http://www.securityfocus.com/bid/76849https://launchpad.net/bugs/1449062http://rhn.redhat.com/errata/RHSA-2016-2923.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2991.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0153.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0156.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0282.htmlhttp://www.openwall.com/lists/oss-security/2016/10/06/8http://www.securityfocus.com/bid/76849https://launchpad.net/bugs/1449062
2016-10-07
Published