GHSA-vq76-rxx3-4r4r · Severity: high · Ecosystem: pip — OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Conclusion & alert: CVE-2017-17051 is rated Moderate Risk (62.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.97%). Core evidence: EPSS rose +1.13% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.84% | 1.97% | +1.13% |
| 2 | 2025-03-30 | 2.83% | 0.84% | -1.98% |
| 3 | 2025-03-29 | — | 2.83% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.6 | 3.0 | HIGH |
|
3.9 | 4.0 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
GHSA-vq76-rxx3-4r4r · Severity: high · Ecosystem: pip — OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2017-17051 not yet assigned priority: Debian including 1 source packages (nova), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-17051 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2017-17051 |
ubuntu
|
medium | CVE-2017-17051 medium priority: Ubuntu including 1 source packages (nova), 6 status rows across 6 suites (artful, bionic, trusty, upstream, xenial, zesty): not-affected 2, DNE 1, ignored 1, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2017-17051 |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/102102 | Third Party Advisory VDB Entry |
| https://launchpad.net/bugs/1732976 | Issue Tracking Third Party Advisory |
| https://review.openstack.org/521662 | Vendor Advisory |
| https://review.openstack.org/523214 | Vendor Advisory |
| https://security.openstack.org/ossa/OSSA-2017-006.html | Vendor Advisory |