CVE-2017-18191High· 7.5▾ TwilightOpenStack Nova Denial of service attack on the compute host
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.8%
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
nova >= 15.0.0, < 15.1.1nova >= 16.0.0, < 16.1.2Upgrade to a patched release:
nova 15.1.1nova 16.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2017-16239Medium· 6.5OpenStack Nova Filter Scheduler Bypass
CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2011-4596MediumOpenStack Nova Multiple directory traversal vulnerabilities
CVE-2012-1585MediumOpenStack Nova Long server names grow nova-api log files significantly