{"id":"CVE-2015-3241","aliases":["GHSA-3vx7-xff6-h2vx","PYSEC-2026-861"],"title":"OpenStack Nova instance migration process does not stop when instance is deleted","summary":"OpenStack Nova instance migration process does not stop when instance is deleted","severity":"medium","vendor":"nova","product":"nova","ecosystem":"pip","affected":["nova < 112.0.0.0b3"],"patched":["nova 112.0.0.0b3"],"published":"2022-05-14","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:29.768180166Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3vx7-xff6-h2vx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3241"},{"url":"https://github.com/openstack/nova/commit/7ab75d5b0b75fc3426323bef19bf436a258b9707"},{"url":"https://github.com/openstack/nova/commit/b5020a047fc487f35b76fc05f31e52665a1afda1"},{"url":"https://github.com/openstack/nova/commit/bf23643e36c8764b4bd532546a2cc04385fe0cff"},{"url":"https://access.redhat.com/errata/RHSA-2015:1723"},{"url":"https://access.redhat.com/errata/RHSA-2015:1898"},{"url":"https://access.redhat.com/security/cve/CVE-2015-3241"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1232782"},{"url":"https://github.com/openstack/nova"},{"url":"https://github.com/openstack/ossa/blob/482576204dec96f580817b119e3166d71c757731/ossa/OSSA-2015-015.yaml"},{"url":"https://launchpad.net/bugs/1387543"},{"url":"https://security.openstack.org/ossa/OSSA-2015-015.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1723.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1898.html"},{"url":"http://www.securityfocus.com/bid/75372"}],"tags":["osv","pip"],"epss":0.0348,"epssPercentile":0.88582,"ingestedAt":"2026-07-08T18:25:45.173Z","slug":"CVE-2015-3241","body":"## Overview\n\nOpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.\n\n## Affected packages\n\n- `nova < 112.0.0.0b3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nova 112.0.0.0b3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}