[openstack-announce] [OSSA 2015-020] Glance storage overrun (CVE-2015-5286)

Tristan Cacqueray tdecacqu at redhat.com
Fri Oct 2 15:00:15 UTC 2015


=====================================
OSSA-2015-020: Glance storage overrun
=====================================

:Date: October 01, 2015
:CVE: CVE-2015-5286


Affects
~~~~~~~
- Glance: <=2014.2.3, >=2015.1.0, <=2015.1.1


Description
~~~~~~~~~~~
Mike Fedosin and Alexei Galkin from Mirantis reported a vulnerability
in Glance. By deleting images that are being uploaded using a token
that is about to expire, a malicious user can overcome the storage
quota and accumulate untracked image data in the backend resulting in
potential resource exhaustion and denial of service. All Glance setups
using the V1 API are affected and all setups using the V2 API with the
registry db_api enabled are affected.


Patches
~~~~~~~
- https://review.openstack.org/229946 (Juno)
- https://review.openstack.org/229975 (Juno)
- https://review.openstack.org/229945 (Kilo)
- https://review.openstack.org/229973 (Kilo)
- https://review.openstack.org/230056 (Liberty)
- https://review.openstack.org/229972 (Liberty)
- https://review.openstack.org/229943 (Mitaka)
- https://review.openstack.org/229971 (Mitaka)


Credits
~~~~~~~
- Mike Fedosin from Mirantis (CVE-2015-5286)
- Alexei Galkin from Mirantis (CVE-2015-5286)


References
~~~~~~~~~~
- https://bugs.launchpad.net/bugs/1498163
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5286


Notes
~~~~~
- This fix will be included in future 2014.2.4 (juno) and 2015.1.2
  (kilo) releases.

--
Tristan Cacqueray
OpenStack Vulnerability Management Team

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: OpenPGP digital signature
URL: <http://lists.openstack.org/pipermail/openstack-announce/attachments/20151002/a2969c6c/attachment.pgp>


More information about the OpenStack-announce mailing list