CVE-2016-7498
medium
CVSS v3
6.5
CVSS v2
6.8
VIR risk
6.5
Description
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7498
Vendor advisory: secalert@redhat.com — https://security.openstack.org/ossa/OSSA-2016-011.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 2:13.1.0-1 |
| debian | bullseye | fixed | 2:13.1.0-1 |
| debian | forky | fixed | 2:13.1.0-1 |
| debian | sid | fixed | 2:13.1.0-1 |
| debian | trixie | fixed | 2:13.1.0-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openstack | compute_\(nova\) | 13.0.0 | |
References
CWEs
CWE-399
Verify integrity in audit chain (admin only). AS-IS.