CVE-2026-46448 Details
Description
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
A vulnerability in OpenStack Nova's server create API prior to version 33.0.2 allows authenticated users to inject internal scheduler hints. This injection bypasses Placement resource claims and scheduling constraints, such as availability zone, host aggregate, and image trait restrictions. As a result, the affected instance lacks a Placement allocation, potentially leading to resource exhaustion on compute nodes and cross-tenant data persistence on NVMe devices after instance deletion.
Users can update to OpenStack Nova versions 33.0.2 or later. Instructions for applying the update can be found in the OpenStack Nova documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugs.launchpad.net/nova/+bug/2151252 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/16/5 | CVE | Mailing ListThird Party Advisory |
| https://bugs.launchpad.net/nova/+bug/2151252 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://www.openwall.com/lists/oss-security/2026/06/16/5 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack nova | >= 18.0.0, < 31.3.1 >= 32.0.0, < 32.2.1 >= 33.0.0, < 33.0.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | New CVE Received | [email protected] |
| Jun 16, 2026 | CVE Modified | CVE |