OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nova | Openstack | 2014.2 (including) | 2014.2.3 (including) |
Nova | Openstack | 2015.1.0 (including) | 2015.1.1 (including) |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-nova-0:2014.1.5-3.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-nova-0:2014.1.5-5.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | openstack-nova-0:2014.2.3-31.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-nova-0:2015.1.0-18.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-nova-0:2015.1.1-3.el7ost | * |
Nova | Ubuntu | precise | * |
Nova | Ubuntu | trusty | * |
Nova | Ubuntu | upstream | * |
Nova | Ubuntu | utopic | * |