VDB
KO
LOW 2.8

GHSA-hqfx-4x4w-vmwp

Openstack nova qcow format could expose host filesystem information

Details

Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / nova
Introduced in: 0 Fixed in: 12.0.0a0
Fix pip install --upgrade 'nova>=12.0.0a0'

References