CVE-2024-40767
published 2024-07-24CVE-2024-40767: In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing…
PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.94%
58.6th percentile
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | — | — |
| openstack | nova | < 27.4.1 | 27.4.1 |
| openstack | nova | >= 0 < 2:21.2.4-0ubuntu2.11 | 2:21.2.4-0ubuntu2.11 |
| openstack | nova | >= 0 < 3:25.2.1-0ubuntu2.6 | 3:25.2.1-0ubuntu2.6 |
| openstack | nova | >= 0 < 3:29.0.1-0ubuntu1.4 | 3:29.0.1-0ubuntu1.4 |
| openstack | nova | 0 – 27.4.0 | — |
| openstack | nova | >= 28.0.0 < 28.2.1 | 28.2.1 |
| openstack | nova | 28.0.0 – 28.2.0 | — |
| openstack | nova | >= 29.0.0 < 29.1.1 | 29.1.1 |
| openstack | nova | 29.0.0 – 29.1.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
ghsa5.7MEDIUM
osv5.7MEDIUM
vendor_debian5.7LOW
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2024-07-23
CVE-2024-40767 Nova vulnerability
Title: Nova vulnerability
Summary: Nova would allow unintended access to files over the network.
Arnaud Morin discovered that Nova incorrectly handled certain raw format
images. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: Regression VMDK/qcow arbitrary file access
vendor_redhat·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-552 openstack-nova: Regression VMDK/qcow arbitrary file access
openstack-nova: Regression VMDK/qcow arbitrary file access
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
An arbitrary file access flaw was found in Nova. By supplying a RAW format image, a specially crafted QCOW2 image with a backing file path, or a VMDK flat image with a descriptor file path, an authenticated user may conv
Debian
CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
vendor_debian·2024·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
osv·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
GHSA
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
ghsa·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-436 OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
OSV
CVE-2024-40767: In OpenStack Nova before 27
osv·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: In OpenStack Nova before 27
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-24708 [LOW] CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24708 :
OpenStack Nova vulnerability analysis and mitigation
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Source : NVD
## 8.2
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
OpenStack Nova
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
E
Bugzilla
CVE-2024-40767 openstack-nova: Regression VMDK/qcow arbitrary file access
bugzilla·2024-07-10·CVSS 6.5
CVE-2024-40767 [MEDIUM] CVE-2024-40767 openstack-nova: Regression VMDK/qcow arbitrary file access
CVE-2024-40767 openstack-nova: Regression VMDK/qcow arbitrary file access
Arnaud Morin (OVH) reported a vulnerability in Nova. By supplying a raw format image which is actually a specially crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file’s contents from the server resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected.
Discussion:
This issue has been addressed in the following products:
Red Hat OpenStack Platform 17.1 for RHEL 8
Via RHSA-2024:5082 https://access.redhat.com/errata/RHSA-2024:5082
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 17.1 for RHEL 9
Via RHSA-2024:508
https://launchpad.net/bugs/2071734https://security.openstack.orghttps://security.openstack.org/ossa/OSSA-2024-002.htmlhttps://www.openwall.com/lists/oss-security/2024/07/23/2https://launchpad.net/bugs/2071734https://lists.debian.org/debian-lts-announce/2024/09/msg00017.htmlhttps://security.openstack.orghttps://security.openstack.org/ossa/OSSA-2024-002.htmlhttps://www.openwall.com/lists/oss-security/2024/07/23/2
2024-07-24
Published