CVE-2013-7130

EUVD-2014-0035
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
openstackcompute
2012.2
openstackcompute
2013.1
openstackcompute
2013.1.1
openstackcompute
2013.1.2
openstackcompute
2013.1.3
openstackgrizzly
-
openstackhavana
-
openstackicehouse
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nova
bookworm
2:26.2.2-1~deb12u3
fixed
bookworm (security)
2:26.2.2-1~deb12u3
fixed
bullseye
2:22.0.1-2+deb11u1
fixed
bullseye (security)
2:22.4.0-1~deb11u5
fixed
sid
2:30.0.0-1
fixed
trixie
2:30.0.0-1
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nova
lucid
dne
precise
Fixed 2012.1.3+stable-20130423-e52e6912-0ubuntu1.4
released
quantal
ignored
raring
ignored
saucy
Fixed 1:2013.2.3-0ubuntu1.2
released
trusty
dne