Описание
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
A flaw was found in OpenStack Nova. The server creation application programming interface (API) fails to remove specific hint data, leading to instances being created without proper Placement allocation. This can result in a denial of service, as resources may not be correctly assigned or managed for the affected instances.
Отчет
This is an Important flaw in OpenStack Nova where an authenticated user can bypass Placement resource claims and scheduling constraints through the server creation API. This bypass can lead to compute node resource exhaustion and cross-tenant data persistence on NVMe devices, impacting the isolation and resource management within Red Hat OpenStack Platform deployments.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | openstack-nova | Affected | ||
| Red Hat OpenStack Platform 17.1 | openstack-nova | Affected | ||
| Red Hat OpenStack Platform 18.0 | openstack-nova | Affected |
Показывать по
Дополнительная информация
Статус:
8.5 High
CVSS3
Связанные уязвимости
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
In OpenStack Nova before 33.0.2, the server create API does not strip ...
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
8.5 High
CVSS3