Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46448

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 8.5

Описание

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

A flaw was found in OpenStack Nova. The server creation application programming interface (API) fails to remove specific hint data, leading to instances being created without proper Placement allocation. This can result in a denial of service, as resources may not be correctly assigned or managed for the affected instances.

Отчет

This is an Important flaw in OpenStack Nova where an authenticated user can bypass Placement resource claims and scheduling constraints through the server creation API. This bypass can lead to compute node resource exhaustion and cross-tenant data persistence on NVMe devices, impacting the isolation and resource management within Red Hat OpenStack Platform deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2openstack-novaAffected
Red Hat OpenStack Platform 17.1openstack-novaAffected
Red Hat OpenStack Platform 18.0openstack-novaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1173
https://bugzilla.redhat.com/show_bug.cgi?id=2489379openstack-nova: OpenStack Nova: Resource allocation issue due to unstripped hint data in server creation API

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS3: 5.4
nvd
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS3: 5.4
debian
около 2 месяцев назад

In OpenStack Nova before 33.0.2, the server create API does not strip ...

CVSS3: 5.4
github
около 2 месяцев назад

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

8.5 High

CVSS3