CVE-2020-17376
published 2020-08-26CVE-2020-17376: An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot…
PriorityP351high8.3CVSS 3.1
AVNACLPRLUINSUCHIHAL
EPSS
1.71%
74.9th percentile
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:21.1.0-1 (bookworm) | nova 2:21.1.0-1 (bookworm) |
| openstack | nova | < 19.3.1 | 19.3.1 |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2:21.1.0-1 | 2:21.1.0-1 |
| openstack | nova | >= 0 < 2:21.1.0-1 | 2:21.1.0-1 |
| openstack | nova | >= 0 < 2:21.1.0-1 | 2:21.1.0-1 |
| openstack | nova | >= 0 < 2:21.1.0-1 | 2:21.1.0-1 |
| openstack | nova | >= 0 < 19.3.1 | 19.3.1 |
| openstack | nova | >= 0 < 2:17.0.13-0ubuntu5.3 | 2:17.0.13-0ubuntu5.3 |
| openstack | nova | >= 0 < 2:21.2.4-0ubuntu2.2 | 2:21.2.4-0ubuntu2.2 |
| openstack | nova | >= 0 < 2:13.1.4-0ubuntu4.5+esm1 | 2:13.1.4-0ubuntu4.5+esm1 |
| openstack | nova | >= 20.0.0 < 20.3.1 | 20.3.1 |
| openstack | nova | >= 20.0.0 < 20.3.1 | 20.3.1 |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2023-02-13·CVSS 3.3
CVE-2021-3654 [LOW] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Several security issues were fixed in Nova.
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service a
Red Hat
openstack-nova: Soft reboot after live-migration reverts instance to original source domain XML
vendor_redhat·2020-08-25·CVSS 8.3
CVE-2020-17376 [HIGH] CWE-200 openstack-nova: Soft reboot after live-migration reverts instance to original source domain XML
openstack-nova: Soft reboot after live-migration reverts instance to original source domain XML
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
An information disclosure flaw was found in the live migration feature of OpenStack Nova. A user may gain acces
Debian
CVE-2020-17376: nova - An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack N...
vendor_debian·2020·CVSS 8.3
CVE-2020-17376 [HIGH] CVE-2020-17376: nova - An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack N...
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
Scope: local
bookworm: resolved (fixed in 2:21.1.0-1)
bullseye: resolved (fixed in 2:21.1.0-1)
forky: resolved (fixed in 2:21.1.0-1)
sid: resolved (fixed in 2:21.1.0-1)
trixie: resolved (fixed in 2:21.1.0-1)
OSV
nova vulnerabilities
osv·2023-02-13·CVSS 3.3
CVE-2015-9543 [LOW] nova vulnerabilities
nova vulnerabilities
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service attack. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-1
OSV
OpenStack Nova Live migration fails to update persistent domain XML
osv·2022-05-24
CVE-2020-17376 [HIGH] OpenStack Nova Live migration fails to update persistent domain XML
OpenStack Nova Live migration fails to update persistent domain XML
An issue was discovered in Guest.migrate in `virt/libvirt/guest.py` in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
GHSA
OpenStack Nova Live migration fails to update persistent domain XML
ghsa·2022-05-24
CVE-2020-17376 [HIGH] CWE-611 OpenStack Nova Live migration fails to update persistent domain XML
OpenStack Nova Live migration fails to update persistent domain XML
An issue was discovered in Guest.migrate in `virt/libvirt/guest.py` in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
OSV
CVE-2020-17376: An issue was discovered in Guest
osv·2020-08-26·CVSS 8.3
CVE-2020-17376 [HIGH] CVE-2020-17376: An issue was discovered in Guest
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.
No detection rules found.
No public exploits indexed.
2020-08-26
Published