| Name | CVE-2013-4469 |
| Description | OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096. |
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 728605 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| nova (PTS) | bullseye (security), bullseye | 2:22.0.1-2+deb11u1 | fixed |
| bookworm | 2:26.1.0-4 | fixed | |
| trixie, sid | 2:29.0.2-4 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| nova | source | (unstable) | 2013.2-3 | low | 728605 |
[wheezy] - nova <no-dsa> (Minor issue)
CVE for incomplete fix of CVE-2013-2096