Skip to main content
EPSS 0.3%top 73%

CVE-2026-24708: CWE-669 Incorrect Resource Transfer Between Spheres in OpenStack Nova

0
High
Published: 02/18/2026 (02/18/2026, 00:00:00 UTC)
Source: GCVE Database
Vendor/Project: OpenStack
Product: Nova

Description

CVE-2026-24708 is a high-severity vulnerability in OpenStack Nova affecting versions before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. It allows an authenticated user to craft a malicious QCOW2 header on a root or ephemeral disk and trigger an unsafe image resize operation via the Flat image backend, leading to arbitrary file overwrite on the compute host. This can cause data destruction or denial of service. The vulnerability arises because Nova invokes qemu-img without format restrictions. Red Hat has rated this issue as Important and currently does not have an official fix meeting their criteria, though updates are available for some OpenStack Services on OpenShift. Mitigation options are limited and no complete fix is yet available.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

Affected software

Affected versions
=0=31.0.0=32.0.0<30.2.2>=31.0.0 <31.2.1>=32.0.0 <32.1.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:46:26 UTC

Technical Analysis

CVE-2026-24708 is a vulnerability in OpenStack Nova where the interaction with the qemu-img utility lacks strict constraints on disk image formats. An authenticated attacker can craft a QCOW2 header on an ephemeral or root disk image that causes qemu-img to overwrite arbitrary files on the compute host with Nova's write permissions. This flaw arises from unconstrained format handling, leading to potential data destruction or denial of service during instance operations such as resizing. The vulnerability is tracked under CWE-73 (External Control of File Name or Path) and CWE-669 (Improper Control of a Resource Through its Lifetime). Red Hat has issued security advisories and updates for affected versions of Red Hat OpenStack Services on OpenShift 18.0.18 to mitigate this issue.

Potential Impact

An authenticated attacker with access to OpenStack Nova can exploit this vulnerability to overwrite arbitrary files on the compute host. This can result in data destruction or denial of service conditions, impacting the integrity and availability of the host system. Confidentiality is not directly impacted. The vulnerability requires local or authenticated access and has low attack complexity and privileges required. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released security updates for Red Hat OpenStack Services on OpenShift 18.0.18 (openstack-nova-27.5.2-18.0.20260312122217) that address this vulnerability. Applying these official updates is the recommended remediation. Currently, no alternative mitigations meet Red Hat's criteria for ease of use, deployment, or stability. Users should follow Red Hat's guidance and update to the fixed package versions as detailed in the advisory at https://access.redhat.com/errata/RHSA-2026:7884.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:7884
Cve Count
1

Threat ID: 6a2866f48dd33fbd85722277

Added to database: 06/09/2026, 19:18:12 UTC

Last enriched: 08/14/2026, 23:46:26 UTC

Last updated: 09/10/2026, 19:24:58 UTC

Views: 249

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses