Lucene search

K
redhatRedHatRHSA-2016:0018
HistoryJan 11, 2016 - 10:15 a.m.

(RHSA-2016:0018) Important: openstack-nova security update

2016-01-1110:15:30
access.redhat.com
14

EPSS

0.001

Percentile

36.1%

OpenStack Compute (nova) launches and schedules large networks of virtual
machines, creating a redundant and scalable cloud computing platform.
Compute provides the software, control panels, and APIs required to
orchestrate a cloud, including running virtual machine instances and
controlling access through users and projects.

A flaw was discovered in the OpenStack Compute (nova) snapshot feature when
using the libvirt driver. A compute user could overwrite an attached
instance disk with a malicious header specifying a backing file, and then
request a snapshot, causing a file from the compute host to be leaked. This
flaw only affects LVM or Ceph setups, or setups using filesystem storage
with “use_cow_images = False”. (CVE-2015-7548)

This issue was discovered by Matthew Booth of Red Hat OpenStack
Engineering.

All openstack-nova users are advised to upgrade to these updated packages,
which correct this issue.