216.73.217.22

CVE-2026-24708

· Published 18/02/2026 18:24 · Modified 19/02/2026 15:53

Labels: CVE-2026-24708 2026-02-18CVE-2026-24708CWE-669[email protected]

Essential information

Published
18/02/2026 18:24
Modified
19/02/2026 15:53
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

CVSS metrics

Description

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openstack / nova cpe:2.3:a:openstack:nova:<30.2.2:*:*:*:*:*:*:*
openstack / nova cpe:2.3:a:openstack:nova:<31.2.1:*:*:*:*:*:*:*
openstack / nova cpe:2.3:a:openstack:nova:<32.1.1:*:*:*:*:*:*:*

References