4
CVSSv2

CVE-2017-17051

Published: 05/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova 16.0.3

Vendor Advisories

Debian Bug report logs - #883621 nova: CVE-2017-17051: Nova FilterScheduler doubles resource allocations during rebuild with new image Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 5 Dec 2017 20:36:0 ...
Debian Bug report logs - #882009 CVE-2017-16239: Nova Filter Scheduler bypass through rebuild action Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Fri, 17 Nov 2017 15:09:01 UTC Severity: grave Tags: patch, securi ...
An issue was discovered in the default FilterScheduler in OpenStack Nova 1603 By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16 ...