Back

HIGH

openstack-nova: Nova FilterScheduler doubles resource allocations during rebuild with new image

Published Dec 5, 2017

Description

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

Affected products

Remediation

Red Hat statement

This vulnerability was caused by the fix for a prior vulnerability (CVE-2017-16239). No patches for the earlier vulnerability were released for Red Hat OpenStack before the discover of the new vulnerability. Therefore, current versions of Red Hat OpenStack are not affected by this vulnerability.

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 5, 2017
Updated Aug 5, 2024
Reserved Nov 28, 2017

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Dec 5, 2017
Bugzilla 1519231

ENISA EUVD

Assigner mitre
Published Dec 5, 2017
Updated Aug 5, 2024