Bug 856685 (CVE-2013-6437) - VUL-0: CVE-2013-6437: openstack-nova: Nova compute DoS through ephemeral disk backing files
Summary: VUL-0: CVE-2013-6437: openstack-nova: Nova compute DoS through ephemeral disk...
Status: RESOLVED FIXED
Alias: CVE-2013-6437
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Vincent Untz
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-23 08:49 UTC by Victor Pereira
Modified: 2016-04-27 20:01 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-12-23 08:49:35 UTC
CVE-2013-6437


Phil Day from HP reported a vulnerability in the libvirt driver handling
of ephemeral disk backing files on Nova compute nodes. By repeatedly
creating snapshots, changing the os_type to a new random value, and
spawning new instances from the snapshot (and quickly deleting those
instances), an authenticated user could generate lots of different
ephemeral disk backing files and fill up compute node disks, potentially
resulting in a Denial of Service against a Nova setup. Only Nova setups
running the libvirt driver are affected.

Icehouse (development branch) fix:
https://review.openstack.org/62910

Havana fix:
https://review.openstack.org/62912

Grizzly fix:
https://review.openstack.org/62913

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6437
https://bugs.launchpad.net/nova/+bug/1253980
Comment 1 Swamp Workflow Management 2013-12-27 23:00:10 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2014-06-20 12:19:07 UTC
do we need a fix for this?
Comment 3 Vincent Untz 2014-06-20 12:52:07 UTC
We have the fix in Cloud 3; I don't think we have it in 2.0. Do you want an update for 2.0?
Comment 4 Marcus Meissner 2014-06-20 12:55:44 UTC
no need for a cloud 2 fix, also only a denial of service