Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. nova
  4. ›
  5. CVE-2017-18191

CVE-2017-18191: OpenStack Nova Denial of service attack on the compute host

May 13, 2022 (updated May 14, 2024)

An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.

References

  • access.redhat.com/errata/RHSA-2018:2332
  • access.redhat.com/errata/RHSA-2018:2714
  • access.redhat.com/errata/RHSA-2018:2855
  • github.com/advisories/GHSA-ffmh-r67w-m88f
  • github.com/openstack/nova
  • github.com/openstack/nova/commit/0225a61fc4557c1257383a654f0741f7ef2ddeac
  • github.com/openstack/nova/commit/5b64a1936122eeb35f37a09f9d38159e1a224c58
  • github.com/openstack/nova/commit/cd3eb60c2c00bcccfa9ccd4bf9d1a96ae7a5cd88
  • launchpad.net/bugs/1739593
  • nvd.nist.gov/vuln/detail/CVE-2017-18191
  • review.openstack.org/539893
  • security.openstack.org/ossa/OSSA-2018-001.html

Code Behaviors & Features

Detect and mitigate CVE-2017-18191 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 15.0.0 before 15.1.1, all versions starting from 16.0.0 before 16.1.2

Fixed versions

  • 15.1.1
  • 16.1.2

Solution

Upgrade to versions 15.1.1, 16.1.2 or above.

Impact 7.5 HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Source file

pypi/nova/CVE-2017-18191.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:09 +0000.