GHSA-ffmh-r67w-m88f

Suggest an improvement
Source
https://github.com/advisories/GHSA-ffmh-r67w-m88f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ffmh-r67w-m88f/GHSA-ffmh-r67w-m88f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ffmh-r67w-m88f
Aliases
Published
2022-05-13T01:44:36Z
Modified
2024-05-19T02:24:41.377358Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
OpenStack Nova Denial of service attack on the compute host
Details

An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.

References

Affected packages

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.0.0
Fixed
15.1.1

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
16.1.2