CVE-2015-3241
OpenStack Nova instance migration process does not stop when instance is deleted
EPSS 2.0%
Description
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
How to fix CVE-2015-3241
To remediate CVE-2015-3241, upgrade the affected package to a fixed version below.
- Debian/nova—upgrade to 1:12.0.0-2 or later
- PyPI/nova—upgrade to 112.0.0.0b3 or later
Is CVE-2015-3241 being exploited?
Low — EPSS is 2.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1:12.0.0-2
- from 0, < 112.0.0.0b3