Bug 847648 (CVE-2013-4463) - VUL-0: CVE-2013-4463: openstack-nova: ensure we don't boot oversized images
Summary: VUL-0: CVE-2013-4463: openstack-nova: ensure we don't boot oversized images
Status: RESOLVED FIXED
Alias: CVE-2013-4463
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2013-12-31
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: .
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-25 12:58 UTC by Marcus Meissner
Modified: 2014-01-28 15:04 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 4 Swamp Workflow Management 2013-10-25 22:00:24 UTC
bugbot adjusting priority
Comment 5 Marcus Meissner 2013-10-28 11:46:01 UTC
CVE-2013-4469 was also added, new description:

Bernhard M. Wiedemann from SUSE reported a vulnerability in Nova's
control of the size of disk images. By using malicious compressed qcow2
disk images, an authenticated user may consume large amounts of disk
space for each image, potentially resulting in a Denial of Service
attack on Nova compute nodes (CVE-2013-4463). While fixing this issue, P=C3=
=A1draig Brady from Red Hat additionally discovered that OSSA 2013-012 did =
not fully address CVE-2013-2096 in the non-default case where use_cow_image=
s=3DFalse, and malicious qcow images are being transferred from Glance. In =
that specific case, an authenticated user could still consume large amounts=
 of disk space for each instance using the malicious image, potentially als=
o resulting in a Denial of Service attack on Nova compute nodes (CVE-2013-4=
469). The provided fixes address both issues.
Comment 6 Marcus Meissner 2013-11-06 08:11:24 UTC
now public.

OpenStack Security Advisory: 2013-029
CVE: CVE-2013-4463, CVE-2013-4469
Date: October 31, 2013
Title: Potential Nova denial of service through compressed disk images
Reporter: Bernhard M. Wiedemann (SUSE) & Pádraig Brady (Red Hat)
Products: Nova
Affects: All versions

Description:
Bernhard M. Wiedemann from SUSE reported a vulnerability in Nova's
control of the size of disk images. By using malicious compressed qcow2
disk images, an authenticated user may consume large amounts of disk
space for each image, potentially resulting in a Denial of Service
attack on Nova compute nodes (CVE-2013-4463). While fixing this issue,
Pádraig Brady from Red Hat additionally discovered that OSSA 2013-012
did not fully address CVE-2013-2096 in the non-default case where
use_cow_images=False, and malicious qcow images are being transferred
from Glance. In that specific case, an authenticated user could still
consume large amounts of disk space for each instance using the
malicious image, potentially also resulting in a Denial of Service
attack on Nova compute nodes (CVE-2013-4469). The provided fixes
address both issues.

Icehouse (development branch) fix:
https://review.openstack.org/54765

Havana fix:
https://review.openstack.org/54767

Grizzly fix:
https://review.openstack.org/54768

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4463
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4469
https://bugs.launchpad.net/nova/+bug/1206081

Regards,

- -- 
Thierry Carrez
OpenStack Vulnerability Management Team
Comment 7 Vincent Untz 2013-11-21 14:46:00 UTC
Sascha: here are the latest security issues we have.
Comment 10 Swamp Workflow Management 2013-12-17 09:37:48 UTC
The SWAMPID for this issue is 55537.
This issue was rated as moderate.
Please submit fixed packages until 2013-12-31.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 11 Swamp Workflow Management 2014-01-28 11:59:20 UTC
Update released for: openstack-nova, openstack-nova-api, openstack-nova-cells, openstack-nova-cert, openstack-nova-compute, openstack-nova-conductor, openstack-nova-console, openstack-nova-consoleauth, openstack-nova-network, openstack-nova-novncproxy, openstack-nova-objectstore, openstack-nova-scheduler, openstack-nova-test, openstack-nova-vncproxy, openstack-nova-volume, python-nova
Products:
SUSE-CLOUD 2.0 (x86_64)
Comment 13 Swamp Workflow Management 2014-01-28 15:04:41 UTC
SUSE-SU-2014:0149-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 847648,848825
CVE References: CVE-2013-4463,CVE-2013-4497
Sources used:
SUSE Cloud 2.0 (src):    openstack-nova-2013.1.5.a17.g4655df1-0.7.1