{
  "threat_severity" : "Important",
  "public_date" : "2026-02-17T15:00:00Z",
  "bugzilla" : {
    "description" : "openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova",
    "id" : "2430312",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2430312"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-73",
  "details" : [ "An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.", "A flaw in OpenStack Nova’s interaction with the qemu-img utility allows an authenticated user to overwrite arbitrary files on the compute host. This occurs because Nova invokes qemu-img without strictly constraining the disk image format, enabling a malicious user to craft a QCOW2 header on a raw disk and trigger destructive behavior during instance operations such as resize." ],
  "statement" : "This vulnerability is rated Important for Red Hat OpenStack Platform. An authenticated attacker can exploit unconstrained disk format handling in OpenStack Nova when invoking qemu-img. By crafting a QCOW2 header on an ephemeral or root disk, an attacker can cause qemu-img to overwrite arbitrary files on the compute host with Nova's write access, leading to data destruction or denial of service.",
  "acknowledgement" : "Red Hat would like to thank Dan Smith (RedHat) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54757",
    "cpe" : "cpe:/a:redhat:openstack:16.2::el8",
    "package" : "openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost"
  }, {
    "product_name" : "Red Hat OpenStack Services on OpenShift 18.0",
    "release_date" : "2026-04-29T00:00:00Z",
    "advisory" : "RHSA-2026:7884",
    "cpe" : "cpe:/a:redhat:openstack:18.0::el9",
    "package" : "openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Affected",
    "package_name" : "rhosp13/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:13"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Not affected",
    "package_name" : "rhosp12/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel8/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Not affected",
    "package_name" : "rhosp-rhel9/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "openstack-nova",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Not affected",
    "package_name" : "rhosp12/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel8/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel9/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Not affected",
    "package_name" : "rhoso/openstack-nova-compute-rhel9",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Not affected",
    "package_name" : "rhosp12/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel9/openstack-nova-compute",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-24708\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24708\nhttps://bugs.launchpad.net/nova/+bug/2137507" ],
  "name" : "CVE-2026-24708",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}