CVE-2013-7130

NameCVE-2013-7130
DescriptionThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs736465

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nova (PTS)buster2:18.1.0-6fixed
buster (security)2:18.1.0-6+deb10u1fixed
bullseye2:22.0.1-2fixed
bookworm, sid2:26.0.0~rc1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
novasource(unstable)2013.2.2low736465

Notes

[wheezy] - nova <no-dsa> (Minor issue)
https://bugs.launchpad.net/nova/+bug/1251590

Search for package or bug name: Reporting problems