VDB
Sign up
HIGH8.6

PYSEC-2026-692

OpenStack Nova DoS by rebuilding the same instance with a new image multiple times

Quick fix

PYSEC-2026-692 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=16.0.4'

Details

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: 16.0.4
Fixpip install --upgrade 'nova>=16.0.4'

References