CVE-2017-17051
published 2017-12-05CVE-2017-17051: An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user…
PriorityP340high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
EPSS
1.97%
78.2th percentile
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:16.0.3-6 (bookworm) | nova 2:16.0.3-6 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 2:16.0.3-6 | 2:16.0.3-6 |
| openstack | nova | >= 0 < 16.0.4 | 16.0.4 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
vendor_redhat·2017-12-05·CVSS 6.5
CVE-2017-17051 [MEDIUM] CWE-400 openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Statement: This vulnerability was caused by the fix for a prior vulnerability (CVE-2017-16239). No patches for the earlier vulnerability were released for Red Hat OpenStack before the discover of the new vulnerabili
Debian
CVE-2017-17051: nova - An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3....
vendor_debian·2017·CVSS 6.5
CVE-2017-17051 [MEDIUM] CVE-2017-17051: nova - An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3....
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Scope: local
bookworm: resolved (fixed in 2:16.0.3-6)
bullseye: resolved (fixed in 2:16.0.3-6)
forky: resolved (fixed in 2:16.0.3-6)
sid: resolved (fixed in 2:16.0.3-6)
trixie: resolved (fixed in 2:16.0.3-6)
OSV
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
osv·2022-05-13·CVSS 6.5
CVE-2017-17051 [MEDIUM] OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
GHSA
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
ghsa·2022-05-13·CVSS 6.5
CVE-2017-17051 [MEDIUM] CWE-400 OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
OSV
CVE-2017-17051: An issue was discovered in the default FilterScheduler in OpenStack Nova 16
osv·2017-12-05·CVSS 6.5
CVE-2017-17051 [MEDIUM] CVE-2017-17051: An issue was discovered in the default FilterScheduler in OpenStack Nova 16
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102102https://launchpad.net/bugs/1732976https://review.openstack.org/521662https://review.openstack.org/523214https://security.openstack.org/ossa/OSSA-2017-006.htmlhttp://www.securityfocus.com/bid/102102https://launchpad.net/bugs/1732976https://review.openstack.org/521662https://review.openstack.org/523214https://security.openstack.org/ossa/OSSA-2017-006.html
2017-12-05
Published