VDB
KO
HIGH 7.5

GHSA-g2j5-7vgx-6xrx

OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption

Details

The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / cinder
Introduced in: 0 Fixed in: 7.0.2
Fix pip install --upgrade 'cinder>=7.0.2'
PyPI / cinder
Introduced in: 8.0.0 Fixed in: 9.0.0
Fix pip install --upgrade 'cinder>=9.0.0'
PyPI / glance
Introduced in: 0 Fixed in: 14.0.0
Fix pip install --upgrade 'glance>=14.0.0'
PyPI / nova
Introduced in: 0 Fixed in: 12.0.4
Fix pip install --upgrade 'nova>=12.0.4'

References