[Openstack] [OSSA 2012-011] Compute node filesystem injection/corruption (CVE-2012-3447)

Eric Windisch eric at cloudscaling.com
Wed Aug 8 00:56:44 UTC 2012


> 
> - if the user specifies an image from glance for the injection to occur
> to. This is almost certainly functionality that you're not going to like
> for the reasons stated above. Its there because v1 did it, and I'm
> willing to remove it if there is a consensus that's the right thing to
> do. However, file IO on this image mount is done as the nova user, not
> root, so that's a tiny bit safer (I hope).
> 

This might be kind-of okay if it uses libguestfs, but I'd need to look more closely at libguestfs before considering it safe. If it is only updating vfat, another option is mtools which is entirely userspace and can be run with some safety on the host. 

Regards,
Eric Windisch





More information about the Openstack mailing list