Vulnerability in OpenStack Nova Affects Encrypted Volume Management
CVE-2017-18191
7.5HIGH
What is CVE-2017-18191?
A flaw exists in OpenStack Nova versions 15.x up to 15.1.0 and 16.x up to 16.1.1, where the detachment and reattachment of encrypted volumes can result in unauthorized access to the underlying raw volume. This vulnerability exposes the LUKS header to potential corruption, which can lead to a denial of service on the compute host. All configurations of Nova that utilize encrypted volumes are impacted, allowing attackers to potentially disrupt services.