Comment 9 for bug 1269418

Revision history for this message
Grant Murphy (gmurphy) wrote : Re: nova rescue doesn't put VM into RESCUE status on vmware

If Jaroslav's analysis is correct than I think we should move to get a CVE assigned for this. (ttx do you agree?).

I've drafted an impact analysis (below). I'm not sure about the versions. I'm assuming this was introduced by this commit: 8db2f23a43cf8aff21d7ef07af742383c275dd76, however I will need a developer to confirm this problem and the cause.

------

Title: Nova VMWare driver leaks rescued images
Reporter: Jaroslav Henner (Red Hat)
Products: Nova
Versions: 2013.2

Description:
Jaroslav Henner from Red Hat reported a vulnerability in Nova. By
requesting Nova place an image into rescue, then deleting
the image an authenticated user my exceed their quota. This can
result in a denial of service via excessive resource consumption.
Only setups using the Nova VMWare driver are affected.