VDB
Sign up
LOW2.8

PYSEC-2026-690

Openstack nova qcow format could expose host filesystem information

Quick fix

PYSEC-2026-690 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=12.0.0a0'

Details

Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: 12.0.0a0
Fixpip install --upgrade 'nova>=12.0.0a0'

References