Description
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3763 | An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected. |
Github GHSA |
GHSA-ffmh-r67w-m88f | OpenStack Nova Denial of service attack on the compute host |
Ubuntu USN |
USN-5866-1 | Nova vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:13:49.181Z
Reserved: 2018-02-19T00:00:00.000Z
Link: CVE-2017-18191
No data.
Status : Modified
Published: 2018-02-19T17:29:00.203
Modified: 2024-11-21T03:19:31.433
Link: CVE-2017-18191
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN