The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_virtualization_manager | Redhat | * | 2.1 (including) |
RHEV Agents (VDSM) | RedHat | * |