openstack-cinder: Data retained after deletion of a ScaleIO volume
Published Aug 27, 2018
7.5
HIGHCVSS 3.1
EPSS 1.24%
Description
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
Affected products
-
- Version up to and including QueensStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| OpenStack Foundation | Openstack-Cinder | n/a |
|
No data.
Red Hat OpenStack Platform 10.0 (Newton)
openstack-cinder-1:9.1.4-50.el7ost
Fixed · RHSA-2019:0917
Red Hat OpenStack Platform 13.0 (Queens)
openstack-cinder-1:12.0.4-2.el7ost
Fixed · RHSA-2018:3601
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
openstack-cinder
Not affected
Red Hat Fuse 7
openstack-cinder
Not affected
Red Hat JBoss Fuse 6
openstack-cinder
Not affected
Red Hat OpenShift Enterprise 3
cinder
Not affected
Red Hat OpenStack Platform 12 (Pike)
openstack-cinder
Out of support scope
Red Hat OpenStack Platform 14 (Rocky)
openstack-cinder
Not affected
Red Hat OpenStack Platform 8 (Liberty)
openstack-cinder
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
openstack-cinder
Will not fix
Red Hat Storage 3
cinder
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-cinder-1:9.1.4-50.el7ost | Fixed | RHSA-2019:0917 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-cinder-1:12.0.4-2.el7ost | Fixed | RHSA-2018:3601 |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | openstack-cinder | Not affected | n/a |
| Red Hat Fuse 7 | openstack-cinder | Not affected | n/a |
| Red Hat JBoss Fuse 6 | openstack-cinder | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | cinder | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | openstack-cinder | Out of support scope | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | openstack-cinder | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | openstack-cinder | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | openstack-cinder | Will not fix | n/a |
| Red Hat Storage 3 | cinder | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
With this update, disabled zero-padding is no longer the default for new volumes. Users can override this behavior by setting the new configuration item, "sio_allow_non_padded_volumes=True". However, the default should not be overridden if multiple tenants will be using volumes from a shared Storage Pool.
Red Hat mitigation
This flaw only affects Red Hat OpenStack Platform deployments which use the third-party EMC ScaleIO driver plugin. To mitigate this flaw, ensure all volumes use zero-padding by updating the ScaleIO storage-pool policy. Note: Only an empty pool's policy can be changed. ~~~ scli --modify_zero_padding_policy (((--protection_domain_id <ID> | --protection_domain_name <NAME>) --storage_pool_name <NAME>) | --storage_pool_id <ID>) (--enable_zero_padding | --disable_zero_padding) Example: scli --modify_zero_padding_policy --protection_domain_name pd10 --storage_pool_name scale1 --enable_zero_padding ~~~
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.24% (0.01244) | 68.19th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.24% (0.01244) | 67.92th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.21% (0.00214) | 59.87th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.21% (0.00214) | 58.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.29% (0.00295) | 64.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (8)
- https://access.redhat.com/errata/RHSA-2018:3601 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0917 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15139 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1599899 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15139 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15139
- https://wiki.openstack.org/wiki/OSSN/OSSN-0084 x_refsource_MISCMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15139
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2018:3601 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:0917 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-15139 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1599899 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15139 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-15139 | ||
| https://wiki.openstack.org/wiki/OSSN/OSSN-0084 | x_refsource_MISCMitigationThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-15139 |
Change history (4)
- MITRE
- CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N to
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N → CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS score changed from 4.8 to
5.1 4.8 → 5.1
- CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N to
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- REDHAT
- CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N to
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N → CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- CVSS score changed from 5.1 to
4.8 5.1 → 4.8
- CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N to
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N