Candidate: CVE-2013-6437 PublicDate: 2014-03-06 15:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6437 http://lists.openstack.org/pipermail/openstack-announce/2013-December/000179.html Description: The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file. Ubuntu-Description: Notes: mdeslaur> OSSA 2013-037 mdeslaur> in precise and quantal, code is in connection.py mdeslaur> seems to be introduced by: mdeslaur> https://git.openstack.org/cgit/openstack/nova/commit/nova/virt/libvirt/driver.py?id=0cecdf4b8632d3a4eea816869796b03e8b928256 Bugs: https://bugs.launchpad.net/nova/+bug/1253980 Priority: medium Discovered-by: Phil Day Assigned-to: CVSS: Patches_nova: upstream: https://review.openstack.org/62910 (icehouse) upstream: https://review.openstack.org/62912 (havana) upstream: https://review.openstack.org/62913 (grizzly) upstream_nova: needs-triage lucid_nova: DNE precise_nova: not-affected quantal_nova: not-affected raring_nova: ignored (reached end-of-life) saucy_nova: not-affected (1:2013.2.2-0ubuntu1) devel_nova: not-affected (1:2014.1~b3-0ubuntu2)