CVE-2015-3241

OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*

History

13 Feb 2023, 00:48

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1232782', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1232782', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1723', 'name': 'https://access.redhat.com/errata/RHSA-2015:1723', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1898', 'name': 'https://access.redhat.com/errata/RHSA-2015:1898', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-3241', 'name': 'https://access.redhat.com/security/cve/CVE-2015-3241', 'tags': [], 'refsource': 'MISC'}
Summary A denial of service flaw was found in the OpenStack Compute (nova) instance migration process. Because the migration process does not terminate when an instance is deleted, an authenticated user could bypass user quota and deplete all available disk space by repeatedly re-sizing and deleting an instance. OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.

02 Feb 2023, 20:20

Type Values Removed Values Added
Summary OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance. A denial of service flaw was found in the OpenStack Compute (nova) instance migration process. Because the migration process does not terminate when an instance is deleted, an authenticated user could bypass user quota and deplete all available disk space by repeatedly re-sizing and deleting an instance.
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1232782 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1723 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1898 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-3241 -

Information

Published : 2015-09-08 15:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-3241

Mitre link : CVE-2015-3241

CVE.ORG link : CVE-2015-3241


JSON object : View

Products Affected

openstack

  • nova
CWE
CWE-399

Resource Management Errors