Vulnerability Name:

CVE-2017-18191 (CCN-139228)

Assigned:2017-12-21
Published:2017-12-21
Updated:2019-10-03
Summary:An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
8.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-18191

Source: MISC
Type: Mailing List, Patch, Third Party Advisory
http://openwall.com/lists/oss-security/2018/04/20/3

Source: BID
Type: Third Party Advisory, VDB Entry
103104

Source: CCN
Type: BID-103104
OpenStack Nova CVE-2017-18191 Local Denial of Service Vulnerability

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:2332

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:2714

Source: REDHAT
Type: Third Party Advisory
RHSA-2018:2855

Source: CCN
Type: Launchpad Bug #1739593
Swapping encrypted volumes can lead to data loss and a possible compute host DOS attack (CVE-2017-18191)

Source: XF
Type: UNKNOWN
openstack-nova-cve201718191-dos(139228)

Source: CONFIRM
Type: Exploit, Issue Tracking, Third Party Advisory
https://launchpad.net/bugs/1739593

Source: CONFIRM
Type: Exploit, Patch, Third Party Advisory
https://review.openstack.org/539893

Source: CCN
Type: OSSA-2018-001
OpenStack Nova

Source: CONFIRM
Type: Patch, Vendor Advisory
https://security.openstack.org/ossa/OSSA-2018-001.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-18191

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openstack:nova:*:*:*:*:*:*:*:* (Version >= 15.0.0 and <= 15.1.0)
  • OR cpe:/a:openstack:nova:*:*:*:*:*:*:*:* (Version >= 16.0.0 and <= 16.1.1)

  • Configuration 2:
  • cpe:/a:redhat:openstack:9:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openstack:10:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openstack:12:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openstack:nova:16.0.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201718191
    V
    CVE-2017-18191
    2022-05-20
    oval:org.opensuse.security:def:58058
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:57108
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:58008
    P
    Security update for ghostscript (Critical)
    2021-09-21
    oval:org.opensuse.security:def:57977
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:57939
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:58082
    P
    Security update for bind (Important)
    2021-02-18
    oval:org.opensuse.security:def:57380
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:56935
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57665
    P
    apache-commons-httpclient on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56535
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57773
    P
    libXrender1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56557
    P
    Security update for libcgroup (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57214
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:57865
    P
    libusbmuxd4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56697
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56534
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:80717
    P
    Security update for openstack-nova (Low)
    2018-05-28
    oval:com.ubuntu.bionic:def:2017181910000000
    V
    CVE-2017-18191 on Ubuntu 18.04 LTS (bionic) - low.
    2018-02-19
    oval:com.ubuntu.artful:def:201718191000
    V
    CVE-2017-18191 on Ubuntu 17.10 (artful) - medium.
    2018-02-19
    oval:com.ubuntu.xenial:def:201718191000
    V
    CVE-2017-18191 on Ubuntu 16.04 LTS (xenial) - low.
    2018-02-19
    oval:com.ubuntu.xenial:def:2017181910000000
    V
    CVE-2017-18191 on Ubuntu 16.04 LTS (xenial) - low.
    2018-02-19
    oval:com.ubuntu.bionic:def:201718191000
    V
    CVE-2017-18191 on Ubuntu 18.04 LTS (bionic) - low.
    2018-02-19
    oval:com.ubuntu.disco:def:2017181910000000
    V
    CVE-2017-18191 on Ubuntu 19.04 (disco) - low.
    2018-02-19
    oval:com.ubuntu.cosmic:def:201718191000
    V
    CVE-2017-18191 on Ubuntu 18.10 (cosmic) - low.
    2018-02-19
    oval:com.ubuntu.cosmic:def:2017181910000000
    V
    CVE-2017-18191 on Ubuntu 18.10 (cosmic) - low.
    2018-02-19
    oval:com.ubuntu.trusty:def:201718191000
    V
    CVE-2017-18191 on Ubuntu 14.04 LTS (trusty) - low.
    2018-02-19
    BACK
    openstack nova *
    openstack nova *
    redhat openstack 9
    redhat openstack 10
    redhat openstack 12
    openstack nova 16.0.3