CVE-2016-7498
published 2016-09-27CVE-2016-7498: OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service…
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.34%
81.7th percentile
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:13.1.0-1 (bookworm) | nova 2:13.1.0-1 (bookworm) |
| openstack | compute | — | — |
| openstack | nova | >= 0 < 2:13.1.0-1 | 2:13.1.0-1 |
| openstack | nova | >= 0 < 2:13.1.0-1 | 2:13.1.0-1 |
| openstack | nova | >= 0 < 2:13.1.0-1 | 2:13.1.0-1 |
| openstack | nova | >= 0 < 2:13.1.0-1 | 2:13.1.0-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: May fail to delete images in resize state regression
vendor_redhat·2016-09-21·CVSS 6.8
CVE-2016-7498 [MEDIUM] CWE-400 openstack-nova: May fail to delete images in resize state regression
openstack-nova: May fail to delete images in resize state regression
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Package: openstack-nova (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: openstack-nova (Red Hat OpenStack Platform 9 (Mitaka)) - Not affected
Debian
CVE-2016-7498: nova - OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute ...
vendor_debian·2016·CVSS 6.8
CVE-2016-7498 [MEDIUM] CVE-2016-7498: nova - OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute ...
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Scope: local
bookworm: resolved (fixed in 2:13.1.0-1)
bullseye: resolved (fixed in 2:13.1.0-1)
forky: resolved (fixed in 2:13.1.0-1)
sid: resolved (fixed in 2:13.1.0-1)
trixie: resolved (fixed in 2:13.1.0-1)
GHSA
GHSA-47vm-xhwp-2v86: OpenStack Compute (nova) 13
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2016-7498 [MEDIUM] GHSA-47vm-xhwp-2v86: OpenStack Compute (nova) 13
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
OSV
CVE-2016-7498: OpenStack Compute (nova) 13
osv·2016-09-27·CVSS 6.8
CVE-2016-7498 [MEDIUM] CVE-2016-7498: OpenStack Compute (nova) 13
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2016/09/21/8http://www.openwall.com/lists/oss-security/2016/09/23/1http://www.securityfocus.com/bid/93068https://security.openstack.org/ossa/OSSA-2016-011.htmlhttp://www.openwall.com/lists/oss-security/2016/09/21/8http://www.openwall.com/lists/oss-security/2016/09/23/1http://www.securityfocus.com/bid/93068https://security.openstack.org/ossa/OSSA-2016-011.html
2016-09-27
Published