Allocation of resources without limits or throttling in Openstack Nova - CVE-2026-24708

 

Allocation of resources without limits or throttling in Openstack Nova - CVE-2026-24708

Published: February 17, 2026


Vulnerability identifier: #VU122995
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24708
CWE-ID: CWE-770
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to the application calls qemu-img without format restrictions for resize. A local user can write malicious QCOW header to a root or ephemeral disk and then trigger a resize to convince Nova’s flat image backend to call qemu-img without a format restriction resulting in an unsafe image resize operation that could destroy data on the host system.


Affected software

Openstack Nova
Debian Linux
Ubuntu
nova (Ubuntu package)
nova (Debian package)
openstack-nova (Red Hat package)

How to mitigate CVE-2026-24708

Install updates from vendor's website.

Openstack Nova - addressed in versions 30.2.2, 31.2.1, 32.1.1
nova (Ubuntu package) - addressed in versions 3:25.2.1-0ubuntu2.10, 3:29.2.0-0ubuntu1.3, 3:32.0.0-0ubuntu1.1
nova (Debian package) - addressed in versions 2:26.2.2-1~deb12u4, 2:31.0.0-6+deb13u2
openstack-nova (Red Hat package) - update to 27.5.2-18.0.20260312122217.c1c6d67.el9ost

External References

Related Security Bulletins