CVE-2017-18191 Details
Description
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack nova | >= 15.0.0, <= 15.1.0 >= 16.0.0, <= 16.1.1 |
CPE
Remediation
| |
| redhat openstack | 9 10 12 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Apr 26, 2019 | Modified Analysis | [email protected] |
| Oct 3, 2018 | CVE Modified | [email protected] |
| Sep 18, 2018 | CVE Modified | [email protected] |
| Aug 21, 2018 | CVE Modified | [email protected] |
| Apr 25, 2018 | CVE Modified | [email protected] |
| Apr 21, 2018 | CVE Modified | [email protected] |
| Mar 17, 2018 | Initial Analysis | [email protected] |
| Feb 24, 2018 | CVE Modified | [email protected] |