CVE-2017-18191

Related Vulnerabilities: CVE-2017-18191  

OpenStack Nova has a vulnerability in the handling of encrypted volumes. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. All Nova installations supporting encrypted volumes are affected.

OpenStack Nova has a vulnerability in the handling of encrypted volumes. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. All Nova installations supporting encrypted volumes are affected.

Find out more about CVE-2017-18191 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 10 (openstack-nova) RHSA-2018:2714 2018-09-17
Red Hat OpenStack Platform 9.0 (openstack-nova) RHSA-2018:2855 2018-10-02
Red Hat OpenStack Platform 12.0 (openstack-nova) RHSA-2018:2332 2018-08-20

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 8.0 (Liberty) openstack-nova Will not fix
Red Hat OpenStack Platform 13.0 (Queens) openstack-nova Not affected
Red Hat OpenStack Platform 11.0 (Ocata) openstack-nova Will not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 openstack-nova Will not fix