CVE-2013-7130

NameCVE-2013-7130
DescriptionThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs736465

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nova (PTS)wheezy2012.1.1-18vulnerable
jessie2014.1.3-11fixed
stretch2:14.0.0-4fixed
stretch (security)2:14.0.0-4+deb9u1fixed
buster, sid2:16.0.3-10fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
novasource(unstable)2013.2.2low736465

Notes

[wheezy] - nova <no-dsa> (Minor issue)
https://bugs.launchpad.net/nova/+bug/1251590

Search for package or bug name: Reporting problems