7.8
CVSSv2

CVE-2017-18191

Published: 19/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in OpenStack Nova 15.x up to and including 15.1.0 and 16.x up to and including 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

redhat openstack 9

redhat openstack 12

redhat openstack 10

Vendor Advisories

Synopsis Moderate: openstack-nova security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 120 (Pike)Red Hat Product Security has rated this update as having a security impactof Moderate A Common ...
Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 100 (Newton)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerabilit ...
OpenStack Nova has a vulnerability in the handling of encrypted volumes By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host All Nova installations supporting encrypted volumes are affected ...