Junglewise Threat Intelligence

CVE-2012-5625: OpenStack Nova information leak in libvirt LVM-backed instances

CVE-2012-5625 · Severity: medium · CVSS 4.3 · Published 2022-05-17

Technologies: nova (PyPI). Vendors: OpenStack, PyPI.

Executive brief

OpenStack Nova, a cloud computing fabric controller, contains a flaw in how it manages virtual machine storage. When using certain storage configurations (LVM-backed instances), the system fails to properly erase data from previously deleted virtual machines before reassigning that storage space to a new user. This could allow a malicious user to read sensitive data belonging to a previous customer, potentially leading to the exposure of private files, credentials, or configuration data.

Technical details

An information disclosure vulnerability exists in OpenStack Compute (Nova) when using the libvirt driver with LVM-backed instances. The root cause is located in the `create_lvm_image` function (and related LVM management utilities), which fails to zero-out or otherwise sanitize blocks on a Physical Volume (PV) when a Logical Volume (LV) is deleted and its space is reallocated to a new instance. Because LVM performs linear mappings, the new LV may contain residual data from the previous occupant. An attacker provisioned on a newly created LV can read the raw block device to recover sensitive information from the previous tenant. The fix involves implementing a mandatory wipe (zeroing) of the logical volume during the removal process.

Affected products

  • OpenStack Nova < 12.0.0a0

Timeline

  • 2012-10-23: disclosed: Bug reported on Launchpad
  • 2012-12-11: advisory: OpenStack Security Advisory (OSSA 2012-020) issued
  • 2012-12-26: advisory: NVD published CVE-2012-5625

References

Related threats