CVE-2026-24708
EUVD-2026-773818.02.2026, 18:24
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | nova | 𝑥 < 30.2.2 | CNA |
| openstack | nova | 31.0.0 ≤ 𝑥 < 31.2.1 | CNA |
| openstack | nova | 32.0.0 ≤ 𝑥 < 32.1.1 | CNA |
Debian Releases
Ubuntu Releases