[OSSA 2014-032] Nova VMware driver still leaks rescued images (CVE-2014-3608)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Invalid
|
Low
|
Andrew Laski | ||
Havana |
Won't Fix
|
Undecided
|
Unassigned | ||
Icehouse |
Fix Released
|
Undecided
|
Cyril Roelandt | ||
OpenStack Security Advisory |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Garth Mollet of Red Hat reported the following when examining the fix for OSSA 2014-017:
.. there may still be a regression in the upstream patches.
With the new patch applied it appears unrescue can still fail if the live vm is in the suspended state. With the new patch unrescue will attempt to poweroff the vm, however poweroff will fail if state == suspended:
# Only PoweredOn VMs can be powered off.
# Raise Exception if VM is suspended
elif pwr_state == "suspended":
reason = _("instance is suspended and cannot be powered off.")
raise exception.
And this exception will be uncaught in the case of a manual unrescue, leading to the same end scenario in Jaroslavs test above, where destroying the vm in error state will leave the -rescue instance.
Red Hat bugzilla reference - https:/
Can we confirm if this is a regression / incomplete fix of bug #1269418 ?
Related branches
- Chuck Short: Pending requested
-
Diff: 22 lines (+12/-0)1 file modifieddebian/changelog (+12/-0)
description: | updated |
Changed in ossa: | |
status: | New → Incomplete |
description: | updated |
Changed in ossa: | |
importance: | Undecided → Medium |
status: | Confirmed → Triaged |
Changed in nova: | |
assignee: | nobody → Andrew Laski (alaski) |
Changed in ossa: | |
status: | Triaged → In Progress |
Changed in nova: | |
importance: | Undecided → Low |
summary: |
- Nova VMware driver still leaks rescued images (CVE-2014-3608) + [OSSA 2014-032] Nova VMware driver still leaks rescued images + (CVE-2014-3608) |
information type: | Private Security → Public Security |
Changed in ossa: | |
status: | Fix Committed → Fix Released |
The bug in the RH bugzilla is set to private so most folks here will be unable to read it. However my comments in the post above refering to "Jaroslavs test above" is refering to testing by Jaroslav Henner that noted that a manual
unrescue would fail if the VM was powered on (due to RH missing the additional patch to power off a powered on
vm when doing unrescue).