OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when usecowimages is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
{
"severity": "LOW",
"github_reviewed": true,
"cwe_ids": [],
"nvd_published_at": "2013-11-02T18:55:00Z",
"github_reviewed_at": "2024-05-14T21:14:01Z"
}