Comment 9 for bug 1524274

Revision history for this message
Matthew Booth (mbooth-9) wrote : Re: Unprivileged api user can access host data using instance snapshot

use_cow_images = True is only used by filesystem storage. Systems which set use_cow_images = True and use filesystem storage are not vulnerable. Everything else is vulnerable. For clarity:

nfs or local files, use_cow_images = True: not vulnerable
nfs or local files, use_cow_images = False: vulnerable
ceph, lvm, ploop: vulnerable

Essentially, anything which stores raw data is vulnerable.