CVE-2015-3241
Publication date 8 September 2015
Last updated 24 July 2024
Ubuntu priority
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Status
Package | Ubuntu Release | Status |
---|---|---|
nova | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1:2014.1.5-0ubuntu1.7
|
|
Notes
mdeslaur
from announcement: "This fix requires oslo.concurrency >= 1.8.2 for Kilo and >= 2.3.0 for Liberty. Juno fix embeds a patched version of oslo.concurrency."
Patch details
Package | Patch details |
---|---|
nova |
|
References
Related Ubuntu Security Notices (USN)
- USN-3449-1
- OpenStack Nova vulnerabilities
- 11 October 2017