CVE-2014-3608
Publication date 6 October 2014
Last updated 24 July 2024
Ubuntu priority
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Status
Package | Ubuntu Release | Status |
---|---|---|
nova | ||
14.04 LTS trusty |
Fixed 1:2014.1.3-0ubuntu1
|
|
Notes
jdstrand
requires use with unsupported VMware ESX driver. This is not compiled in to libvirt in the Ubuntu archive, which makes this code path unavailable in Ubuntu
Patch details
Package | Patch details |
---|---|
nova |
|
References
Related Ubuntu Security Notices (USN)
- USN-2407-1
- OpenStack Nova vulnerabilities
- 11 November 2014