CVE-2026-24708
Vulnerability Summary
Timeline
Description
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
CVSS Metrics
- v3.1•HIGH•Score: 8.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Trends
Current EPSS score: 0.38%• Percentile: 32%
Techniques & Countermeasures
- CWE-669•Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
- CWE-73•External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Affected Systems
- debian•nova
< 2:22.4.0-1~deb11u7 | < 2:26.2.2-1~deb12u4 | < 2:31.0.0-6+deb13u2 | < 2:32.1.0-7
- openstack•nova
< 30.2.2 | ≥ 31.0.0, < 31.2.1 | ≥ 32.0.0, < 32.1.1
- PyPI•nova
≥ 31.0.0.0rc1, ≤ 31.2.0 | ≤ 30.2.1 | ≥ 32.0.0.0rc1, ≤ 32.1.0
- redhat•openstack-nova
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-api
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-common
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-compute
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-conductor
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-migration
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-novncproxy
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-scheduler
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-serialproxy
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•openstack-nova-spicehtml5proxy
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
- redhat•python3-nova
< 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost
References (18)
- https://bugs.launchpad.net/nova/+bug/2137507
- https://www.openwall.com/lists/oss-security/2026/02/17/7
- https://lists.debian.org/debian-lts-announce/2026/02/msg00025.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-24708
- https://github.com/openstack/nova/commit/3eba22ff09c81a61750fbb4882e5f1f01a20fdf5
- https://github.com/openstack/nova
- https://access.redhat.com/security/cve/CVE-2026-24708
- https://bugzilla.redhat.com/show_bug.cgi?id=2430312
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24708.json
- https://access.redhat.com/errata/RHSA-2026:7884
- https://pypi.org/project/nova
- https://github.com/advisories/GHSA-m4f3-qp2w-gwh6
- https://security-tracker.debian.org/tracker/CVE-2026-24708
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7884.json
- https://www.cve.org/CVERecord?id=CVE-2026-24708
- https://access.redhat.com/errata/RHSA-2026:54757
- https://access.redhat.com/errata/RHSA-2026:66401