OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nova | Openstack | 2014.2 (including) | 2014.2.4 (excluding) |
Nova | Openstack | 2015.1.0 (including) | 2015.1.2 (excluding) |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-nova-0:2014.1.5-3.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-nova-0:2014.1.5-5.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | openstack-nova-0:2014.2.3-31.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-nova-0:2015.1.1-3.el7ost | * |
Nova | Ubuntu | precise | * |
Nova | Ubuntu | trusty | * |