CVE-2017-18191
published 2018-02-19CVE-2017-18191: An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.75%
88.7th percentile
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:17.0.0-1 (bookworm) | nova 2:17.0.0-1 (bookworm) |
| openstack | nova | >= 0 < 2:17.0.0-1 | 2:17.0.0-1 |
| openstack | nova | >= 0 < 2:17.0.0-1 | 2:17.0.0-1 |
| openstack | nova | >= 0 < 2:17.0.0-1 | 2:17.0.0-1 |
| openstack | nova | >= 0 < 2:17.0.0-1 | 2:17.0.0-1 |
| openstack | nova | >= 0 < 2:17.0.13-0ubuntu5.3 | 2:17.0.13-0ubuntu5.3 |
| openstack | nova | >= 0 < 2:21.2.4-0ubuntu2.2 | 2:21.2.4-0ubuntu2.2 |
| openstack | nova | >= 0 < 2:13.1.4-0ubuntu4.5+esm1 | 2:13.1.4-0ubuntu4.5+esm1 |
| openstack | nova | >= 15.0.0 < 15.1.1 | 15.1.1 |
| openstack | nova | 15.0.0 – 15.1.0 | — |
| openstack | nova | >= 16.0.0 < 16.1.2 | 16.1.2 |
| openstack | nova | 16.0.0 – 16.1.1 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2023-02-13·CVSS 3.3
CVE-2021-3654 [LOW] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Several security issues were fixed in Nova.
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service a
Red Hat
openstack-nova: Swapping encrypted volumes can allow an attacker to corrupt the LUKS header causing a denial of service in the host
vendor_redhat·2018-02-19·CVSS 7.5
CVE-2017-18191 [HIGH] CWE-20 openstack-nova: Swapping encrypted volumes can allow an attacker to corrupt the LUKS header causing a denial of service in the host
openstack-nova: Swapping encrypted volumes can allow an attacker to corrupt the LUKS header causing a denial of service in the host
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
OpenStack Nova has a vulnerability in the handling of encrypted volumes. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting
Debian
CVE-2017-18191: nova - An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 1...
vendor_debian·2017·CVSS 7.5
CVE-2017-18191 [HIGH] CVE-2017-18191: nova - An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 1...
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
Scope: local
bookworm: resolved (fixed in 2:17.0.0-1)
bullseye: resolved (fixed in 2:17.0.0-1)
forky: resolved (fixed in 2:17.0.0-1)
sid: resolved (fixed in 2:17.0.0-1)
trixie: resolved (fixed in 2:17.0.0-1)
OSV
nova vulnerabilities
osv·2023-02-13·CVSS 3.3
CVE-2015-9543 [LOW] nova vulnerabilities
nova vulnerabilities
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service attack. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-1
GHSA
OpenStack Nova Denial of service attack on the compute host
ghsa·2022-05-13
CVE-2017-18191 [HIGH] OpenStack Nova Denial of service attack on the compute host
OpenStack Nova Denial of service attack on the compute host
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
OSV
OpenStack Nova Denial of service attack on the compute host
osv·2022-05-13
CVE-2017-18191 [HIGH] OpenStack Nova Denial of service attack on the compute host
OpenStack Nova Denial of service attack on the compute host
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
OSV
CVE-2017-18191: An issue was discovered in OpenStack Nova 15
osv·2018-02-19·CVSS 7.5
CVE-2017-18191 [HIGH] CVE-2017-18191: An issue was discovered in OpenStack Nova 15
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
No detection rules found.
No public exploits indexed.
http://openwall.com/lists/oss-security/2018/04/20/3http://www.securityfocus.com/bid/103104https://access.redhat.com/errata/RHSA-2018:2332https://access.redhat.com/errata/RHSA-2018:2714https://access.redhat.com/errata/RHSA-2018:2855https://launchpad.net/bugs/1739593https://review.openstack.org/539893https://security.openstack.org/ossa/OSSA-2018-001.htmlhttp://openwall.com/lists/oss-security/2018/04/20/3http://www.securityfocus.com/bid/103104https://access.redhat.com/errata/RHSA-2018:2332https://access.redhat.com/errata/RHSA-2018:2714https://access.redhat.com/errata/RHSA-2018:2855https://launchpad.net/bugs/1739593https://review.openstack.org/539893https://security.openstack.org/ossa/OSSA-2018-001.html
2018-02-19
Published