Hyper-V: swapped disks after host reboot
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Fix Released
|
High
|
Lucian Petrut | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
As the disk number of iSCSI attached disks can change after host reboot, passthrough attached volumes can get attached in this case.
This bug was partially fixed during Icehouse by this patch:
https:/
One of the issues with this patch is that it only handles SCSI attached disks, for which reason this issue continues to occur when having generation 1 VMs booted from volume, in which case the disk will be placed on the IDE controller.
In this case, one instance may end up booting from another tenant's volume, which is a critical security issue.
Also, it assumes that the block device info volume order matches the according disk controller slot order, which is wrong.
Related bug: https:/
description: | updated |
Changed in nova: | |
assignee: | nobody → Lucian Petrut (petrutlucian94) |
description: | updated |
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.