CVE-2026-24708
published 2026-02-18CVE-2026-24708: An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk…
PriorityP346high8.2CVSS 3.1
AVNACHPRLUINSCCNIHAH
EPSS
0.34%
26.4th percentile
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:26.2.2-1~deb12u4 (bookworm) | nova 2:26.2.2-1~deb12u4 (bookworm) |
| openstack | nova | < 30.2.2 | 30.2.2 |
| openstack | nova | >= 0 < 2:22.4.0-1~deb11u7 | 2:22.4.0-1~deb11u7 |
| openstack | nova | >= 0 < 2:26.2.2-1~deb12u4 | 2:26.2.2-1~deb12u4 |
| openstack | nova | >= 0 < 2:31.0.0-6+deb13u2 | 2:31.0.0-6+deb13u2 |
| openstack | nova | >= 0 < 2:32.1.0-7 | 2:32.1.0-7 |
| openstack | nova | 0 – 30.2.1 | — |
| openstack | nova | >= 31.0.0 < 31.2.1 | 31.2.1 |
| openstack | nova | 31.0.0.0rc1 – 31.2.0 | — |
| openstack | nova | >= 32.0.0 < 32.1.1 | 32.1.1 |
| openstack | nova | 32.0.0.0rc1 – 32.1.0 | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
vendor_redhat·2026-02-17·CVSS 8.2
CVE-2026-24708 [HIGH] CWE-73 openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
A flaw in OpenStack Nova’s interaction with the qemu-img utility allows an authenticated user to overwrite arbitrary files on the compute host. This occurs because Nova invokes qemu-img without strictl
Ubuntu
Nova vulnerability
vendor_ubuntu·2026-02-17
CVE-2026-24708 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to destroy data.
Dan Smith discovered that Nova incorrectly called qemu-img without a format
restriction when resizing disks. An attacker could possibly use this issue
to destroy data on the host system.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2026-24708: nova - An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 3...
vendor_debian·2026·CVSS 8.2
CVE-2026-24708 [HIGH] CVE-2026-24708: nova - An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 3...
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Scope: local
bookworm: resolved (fixed in 2:26.2.2-1~deb12u4)
bullseye: resolved (fixed in 2:22.4.0-1~deb11u7)
forky: resolved (fixed in 2:32.1.0-7)
sid: resolved (fixed in 2:32.1.0-7)
trixie: resolved (fixed in 2:31.0.0-6+deb13u2)
OSV
CVE-2026-24708: An issue was discovered in OpenStack Nova before 30
osv·2026-02-18·CVSS 8.2
CVE-2026-24708 [HIGH] CVE-2026-24708: An issue was discovered in OpenStack Nova before 30
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
GHSA
OpenStack Nova calls qemu-img without format restrictions for resize
ghsa·2026-02-18
CVE-2026-24708 [HIGH] CWE-669 OpenStack Nova calls qemu-img without format restrictions for resize
OpenStack Nova calls qemu-img without format restrictions for resize
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
OSV
OpenStack Nova calls qemu-img without format restrictions for resize
osv·2026-02-18
CVE-2026-24708 [HIGH] OpenStack Nova calls qemu-img without format restrictions for resize
OpenStack Nova calls qemu-img without format restrictions for resize
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-24708 [LOW] CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24708 :
OpenStack Nova vulnerability analysis and mitigation
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Source : NVD
## 8.2
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
OpenStack Nova
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
E
Bugzilla
CVE-2026-24708 openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
bugzilla·2026-01-16·CVSS 8.2
CVE-2026-24708 [HIGH] CVE-2026-24708 openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
CVE-2026-24708 openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
Unconstrained disk format handling vulnerability in OpenStack Nova when invoking the qemu-img utility. The flaw occurs because Nova does not strictly enforce the expected disk image format before calling qemu-img. An authenticated attacker can write a crafted QCOW2 header to a raw ephemeral or root disk. When Nova later performs operations such as instance resize, qemu-img interprets the disk as QCOW2 and overwrites arbitrary files on the compute host that Nova has write access to. This can be exploited without additional privileges or user interaction, allowing attackers to destroy other users’ data, corrupt Nova-managed files, or cause denial of service on th
https://bugs.launchpad.net/nova/+bug/2137507https://www.openwall.com/lists/oss-security/2026/02/17/7https://lists.debian.org/debian-lts-announce/2026/02/msg00025.htmlhttps://access.redhat.com/errata/RHSA-2026:7884https://access.redhat.com/security/cve/CVE-2026-24708https://bugzilla.redhat.com/show_bug.cgi?id=2430312https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24708.json
2026-02-18
Published