CVE-2013-4463

EPSS 0.15%

OpenStack Nova denial of service through compressed disk images

Published: 5/17/2022Modified: 4/28/2026

Description

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

Affected packages (2)

References (9)