CVE-2017-18191
moderate-risk
Published 2018-02-19
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
Do I need to act?
~
2.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
References (16)
Mailing List
http://openwall.com/lists/oss-security/2018/04/20/3
Third Party Advisory
http://www.securityfocus.com/bid/103104
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2332
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2714
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2855
Mailing List
http://openwall.com/lists/oss-security/2018/04/20/3
Third Party Advisory
http://www.securityfocus.com/bid/103104
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2332
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2714
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2855
42
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
6/34 · Minimal
Exposure
10/34 · Low