CVE-2016-2140
published 2016-04-12CVE-2016-2140: The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to…
PriorityP433medium5.3CVSS 3.0
AVNACHPRLUINSUCHINAN
EPSS
2.09%
79.5th percentile
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:13.0.0-1 (bookworm) | nova 2:13.0.0-1 (bookworm) |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | nova | >= 0 < 1:2014.1.5-0ubuntu1.7 | 1:2014.1.5-0ubuntu1.7 |
| openstack | nova | >= 12.0.0 < 12.0.3 | 12.0.3 |
| openstack | nova | >= 12.0.0 < 12.0.3 | 12.0.3 |
| openstack | nova | >= 2015.1.0 < 2015.1.4 | 2015.1.4 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.8
CVE-2015-3241 [MEDIUM] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: Several security issues were fixed in OpenStack Nova.
George Shuklin discovered that OpenStack Nova incorrectly handled the
migration process. A remote authenticated user could use this issue to
consume resources, resulting in a denial of service. (CVE-2015-3241)
George Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly
handled deleting instances. A remote authenticated user could use this
issue to consume disk resources, resulting in a denial of service.
(CVE-2015-3280)
It was discovered that OpenStack Nova incorrectly limited qemu-img calls. A
remote authenticated user could use this issue to consume resources,
resulting in a denial of service. (CVE-2015-5162)
Matthew Booth discovered that OpenStack Nova incorrectly han
Red Hat
openstack-nova: Host data leak through resize/migration
vendor_redhat·2016-03-08·CVSS 5.3
CVE-2016-2140 [MEDIUM] CWE-200 openstack-nova: Host data leak through resize/migration
openstack-nova: Host data leak through resize/migration
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
An information-exposure flaw was found in the OpenStack Compute (nova) resize and migrate functionality. An authenticated user could write a malicious qcow header to an ephemeral or root disk, referencing a block device as a backing file. With a subsequent resize or migration, file system content on the specified device would be leaked to the user. Only setups using libvirt with raw storage and "use_cow_images = False" were affected.
Package: openstack-nova
Debian
CVE-2016-2140: nova - The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x...
vendor_debian·2016·CVSS 5.3
CVE-2016-2140 [MEDIUM] CVE-2016-2140: nova - The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x...
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
Scope: local
bookworm: resolved (fixed in 2:13.0.0-1)
bullseye: resolved (fixed in 2:13.0.0-1)
forky: resolved (fixed in 2:13.0.0-1)
sid: resolved (fixed in 2:13.0.0-1)
trixie: resolved (fixed in 2:13.0.0-1)
GHSA
OpenStack Nova host data access through resize/migration
ghsa·2022-05-14
CVE-2016-2140 [MEDIUM] CWE-200 OpenStack Nova host data access through resize/migration
OpenStack Nova host data access through resize/migration
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
OSV
OpenStack Nova host data access through resize/migration
osv·2022-05-14
CVE-2016-2140 [MEDIUM] OpenStack Nova host data access through resize/migration
OpenStack Nova host data access through resize/migration
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
OSV
nova vulnerabilities
osv·2017-10-11·CVSS 6.8
CVE-2015-3241 [MEDIUM] nova vulnerabilities
nova vulnerabilities
George Shuklin discovered that OpenStack Nova incorrectly handled the
migration process. A remote authenticated user could use this issue to
consume resources, resulting in a denial of service. (CVE-2015-3241)
George Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly
handled deleting instances. A remote authenticated user could use this
issue to consume disk resources, resulting in a denial of service.
(CVE-2015-3280)
It was discovered that OpenStack Nova incorrectly limited qemu-img calls. A
remote authenticated user could use this issue to consume resources,
resulting in a denial of service. (CVE-2015-5162)
Matthew Booth discovered that OpenStack Nova incorrectly handled snapshots.
A remote authenticated user could use this issue to read arbitrar
OSV
CVE-2016-2140: The libvirt driver in OpenStack Compute (Nova) before 2015
osv·2016-04-12·CVSS 5.3
CVE-2016-2140 [MEDIUM] CVE-2016-2140: The libvirt driver in OpenStack Compute (Nova) before 2015
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2140 openstack-nova: Host data leak through resize/migration [fedora-all]
bugzilla·2016-03-08·CVSS 5.3
CVE-2016-2140 [MEDIUM] CVE-2016-2140 openstack-nova: Host data leak through resize/migration [fedora-all]
CVE-2016-2140 openstack-nova: Host data leak through resize/migration [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2016-2140 openstack-nova: Host data leak through resize/migration
bugzilla·2016-03-01·CVSS 5.3
CVE-2016-2140 [MEDIUM] CVE-2016-2140 openstack-nova: Host data leak through resize/migration
CVE-2016-2140 openstack-nova: Host data leak through resize/migration
It was reported that by overwriting an ephemeral or root disk with a malicious image before requesting a resize, an authenticated user may be able to read arbitrary files from the compute host. Only setups using libvirt driver with raw storage and setting "use_cow_images = False" (not default) are affected.
Affected versions: =12.0.0 External references:
>
> http://seclists.org/oss-sec/2016/q1/563
There is an errata released, which concerns these patches.
http://seclists.org/oss-sec/2016/q1/579
---
(In reply to Andrej Nemec from comment #21)
> (In reply to Andrej Nemec from comment #19)
> > External references:
> >
> > http://seclists.org/oss-sec/2016/q1/563
>
> There is an errata released, which concerns these pat
http://www.openwall.com/lists/oss-security/2016/03/08/6http://www.securityfocus.com/bid/84277https://bugs.launchpad.net/nova/+bug/1548450https://security.openstack.org/ossa/OSSA-2016-007.htmlhttp://www.openwall.com/lists/oss-security/2016/03/08/6http://www.securityfocus.com/bid/84277https://bugs.launchpad.net/nova/+bug/1548450https://security.openstack.org/ossa/OSSA-2016-007.html
2016-04-12
Published