CVE-2013-7130

NameCVE-2013-7130
DescriptionThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs736465

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nova (PTS)jessie2014.1.3-11fixed
stretch (security), stretch (lts), stretch2:14.0.0-4+deb9u1fixed
buster2:18.1.0-6fixed
buster (security)2:18.1.0-6+deb10u2fixed
bullseye (security), bullseye2:22.0.1-2+deb11u1fixed
bookworm2:26.1.0-4fixed
sid2:29.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
novasource(unstable)2013.2.2low736465

Notes

[wheezy] - nova <no-dsa> (Minor issue)
https://bugs.launchpad.net/nova/+bug/1251590

Search for package or bug name: Reporting problems