CVE-2017-16239
published 2017-11-14CVE-2017-16239: In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
1.41%
69.6th percentile
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:16.0.3-1 (bookworm) | nova 2:16.0.3-1 (bookworm) |
| debian | nova | < nova 2:16.0.3-6 (bookworm) | nova 2:16.0.3-6 (bookworm) |
| openstack | nova | <= 14.0.9 | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-1 | 2:16.0.3-1 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-1 | 2:16.0.3-1 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-1 | 2:16.0.3-1 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-1 | 2:16.0.3-1 |
| openstack | nova | >= 0 < 16.0.4 | 16.0.4 |
| openstack | nova | >= 14.0.0 < 14.0.10 | 14.0.10 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
vendor_redhat·2017-12-05·CVSS 6.5
CVE-2017-17051 [MEDIUM] CWE-400 openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Statement: This vulnerability was caused by the fix for a prior vulnerability (CVE-2017-16239). No patches for the earlier vulnerability were released for Red Hat OpenStack before the discover of the new vulnerabili
Red Hat
openstack-nova: Nova Filter Scheduler bypass through rebuild action
vendor_redhat·2017-11-14·CVSS 6.5
CVE-2017-16239 [MEDIUM] CWE-841 openstack-nova: Nova Filter Scheduler bypass through rebuild action
openstack-nova: Nova Filter Scheduler bypass through rebuild action
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
By rebuilding an instance using a new image, an authenticated user may be able to circumvent the Filter Scheduler, bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter).
Statement: The upstr
Debian
CVE-2017-16239: nova - In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, ...
vendor_debian·2017·CVSS 6.5
CVE-2017-16239 [MEDIUM] CVE-2017-16239: nova - In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, ...
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
Scope: local
bookworm: resolved (fixed in 2:16.0.3-1)
bullseye: resolved (fixed in 2:16.0.3-1)
forky: resolved (fixed in 2:16.0.3-1)
sid: resolved (fixed in 2:16.0.3-1)
trixie: resolved (fixed in 2:16.0.3-1)
Debian
CVE-2017-17051: nova - An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3....
vendor_debian·2017·CVSS 6.5
CVE-2017-17051 [MEDIUM] CVE-2017-17051: nova - An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3....
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Scope: local
bookworm: resolved (fixed in 2:16.0.3-6)
bullseye: resolved (fixed in 2:16.0.3-6)
forky: resolved (fixed in 2:16.0.3-6)
sid: resolved (fixed in 2:16.0.3-6)
trixie: resolved (fixed in 2:16.0.3-6)
GHSA
OpenStack Nova Filter Scheduler Bypass
ghsa·2022-05-13
CVE-2017-16239 [MEDIUM] OpenStack Nova Filter Scheduler Bypass
OpenStack Nova Filter Scheduler Bypass
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
OSV
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
osv·2022-05-13·CVSS 6.5
CVE-2017-17051 [MEDIUM] OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
GHSA
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
ghsa·2022-05-13·CVSS 6.5
CVE-2017-17051 [MEDIUM] CWE-400 OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
OSV
OpenStack Nova Filter Scheduler Bypass
osv·2022-05-13
CVE-2017-16239 [MEDIUM] OpenStack Nova Filter Scheduler Bypass
OpenStack Nova Filter Scheduler Bypass
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
OSV
CVE-2017-17051: An issue was discovered in the default FilterScheduler in OpenStack Nova 16
osv·2017-12-05·CVSS 6.5
CVE-2017-17051 [MEDIUM] CVE-2017-17051: An issue was discovered in the default FilterScheduler in OpenStack Nova 16
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
OSV
CVE-2017-16239: In OpenStack Nova through 14
osv·2017-11-14·CVSS 6.5
CVE-2017-16239 [MEDIUM] CVE-2017-16239: In OpenStack Nova through 14
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-17051 openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
bugzilla·2017-11-30·CVSS 6.5
CVE-2017-17051 [MEDIUM] CVE-2017-17051 openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
CVE-2017-17051 openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
It was found that by repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239 ), however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Bug report:
https://launchpad.net/bugs/1732976
Discussion:
Acknowledgments:
Name: the OpenStack project
Upstream: Matt Riedemann (Huawei)
---
Statement:
This vulnerability was caused by the fix for a prior vulnerability (CVE-2017-16239). No patches for the earlier vulnerability were relea
Bugzilla
CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action [openstack-rdo]
bugzilla·2017-11-14·CVSS 6.5
CVE-2017-16239 [MEDIUM] CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action [openstack-rdo]
CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed since new
Bugzilla
CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action
bugzilla·2017-11-01·CVSS 6.5
CVE-2017-16239 [MEDIUM] CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action
CVE-2017-16239 openstack-nova: Nova Filter Scheduler bypass through rebuild action
By rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected.
Affected versions: =15.0.0 =16.0.0 <=16.0.2
Bug report:
https://launchpad.net/bugs/1664931
Discussion:
Acknowledgments:
Name: the OpenStack project
Upstream: George Shuklin (Servers.com)
---
Created attachment 1346603
Master queens patch
---
Created attachment 1346604
Stable newton patch
---
Created attachment 1346605
Stable pike patch
---
Created attachment 1346606
Stable ocata patch
---
Filed trackers for all versions.
---
Created openstack-nova tr
http://www.securityfocus.com/bid/101950https://access.redhat.com/errata/RHSA-2018:0241https://access.redhat.com/errata/RHSA-2018:0314https://access.redhat.com/errata/RHSA-2018:0369https://launchpad.net/bugs/1664931https://security.openstack.org/ossa/OSSA-2017-005.htmlhttps://www.debian.org/security/2017/dsa-4056http://www.securityfocus.com/bid/101950https://access.redhat.com/errata/RHSA-2018:0241https://access.redhat.com/errata/RHSA-2018:0314https://access.redhat.com/errata/RHSA-2018:0369https://launchpad.net/bugs/1664931https://security.openstack.org/ossa/OSSA-2017-005.htmlhttps://www.debian.org/security/2017/dsa-4056
2017-11-14
Published