suse · CVE-2016-2140

Quick triage

Priority: medium Published: 2021-05-30 13:39:16 UTC Updated: 2023-02-15 01:41:50 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-2140 severity moderate: SUSE including 81 source package names (openstack-ceilometer-5.0.4~a0~dev6-6.1, openstack-ceilometer-agent-central-5.0.4~a0~dev6-6.1, …), 82 product×package rows across 3 product lines (SUSE Cloud 5, SUSE Cloud for SLE 12 Compute Nodes, SUSE OpenStack Cloud 6): Fixed 80, Known Not Affected 2.

Description:

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.

cvelogic Threat Intelligence