Allocation of resources without limits or throttling in Openstack Nova - CVE-2026-24708
Published: February 17, 2026
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to the application calls qemu-img without format restrictions for resize. A local user can write malicious QCOW header to a root or ephemeral disk and then trigger a resize to convince Nova’s flat image backend to call qemu-img without a format restriction resulting in an unsafe image resize operation that could destroy data on the host system.
Affected software
Debian Linux
Ubuntu
nova (Ubuntu package)
nova (Debian package)
openstack-nova (Red Hat package)
How to mitigate CVE-2026-24708
nova (Ubuntu package) - addressed in versions 3:25.2.1-0ubuntu2.10, 3:29.2.0-0ubuntu1.3, 3:32.0.0-0ubuntu1.1
nova (Debian package) - addressed in versions 2:26.2.2-1~deb12u4, 2:31.0.0-6+deb13u2
openstack-nova (Red Hat package) - update to 27.5.2-18.0.20260312122217.c1c6d67.el9ost