CVE-2013-6437

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
06/03/2014
Last modified:
12/04/2025

Description

The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 2013.1 (including) 2013.1.5 (excluding)
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 2013.2 (including) 2013.2.2 (excluding)
cpe:2.3:a:openstack:nova:2014.1:milestone1:*:*:*:*:*:*