Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-46448

Опубликовано: 16 июн. 2026
Источник: debian

Описание

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novafixed2:33.0.1-4package
novano-dsatrixiepackage
novapostponedbookwormpackage
novapostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/16/5

  • https://launchpad.net/bugs/2151252

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS3: 8.5
redhat
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS3: 5.4
nvd
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS3: 5.4
github
около 2 месяцев назад

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints