CVE-2026-24708

Aliases:GHSA-m4f3-qp2w-gwh6PYSEC-2026-2685DEBIAN-CVE-2026-24708RHSA-2026:7884
Advisory lineage Upstream: 0 Downstream: 8
Deferred
Published: 18 Feb 2026, 00:00
Last modified:11 Sept 2026, 12:09

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
v3.1 (cve.org)
EPSS Score
0.38% LOW
0% probability +0.36%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Feb 2026, 00:00
Published
Vulnerability first disclosed
11 Sept 2026, 12:09
Last Modified
Vulnerability information updated

Description

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.

CVSS Metrics

  • v3.1HIGHScore: 8.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Techniques & Countermeasures

  • CWE-669Incorrect Resource Transfer Between Spheres

    The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

  • CWE-73External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

Affected Systems

  • debiannova

    < 2:22.4.0-1~deb11u7 | < 2:26.2.2-1~deb12u4 | < 2:31.0.0-6+deb13u2 | < 2:32.1.0-7

  • openstacknova

    < 30.2.2 | ≥ 31.0.0, < 31.2.1 | ≥ 32.0.0, < 32.1.1

  • PyPInova

    ≥ 31.0.0.0rc1, ≤ 31.2.0 | ≤ 30.2.1 | ≥ 32.0.0.0rc1, ≤ 32.1.0

  • redhatopenstack-nova

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-api

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-common

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-compute

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-conductor

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-migration

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-novncproxy

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-scheduler

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-serialproxy

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatopenstack-nova-spicehtml5proxy

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

  • redhatpython3-nova

    < 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost

References (18)