CVE-2026-24708: Openstack Nova
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Affected products
- Openstack Nova: before 30.2.2 (fixed in 30.2.2); from 31.0.0, before 31.2.1 (fixed in 31.2.1); from 32.0.0, before 32.1.1 (fixed in 32.1.1)
- Red Hat Red Hat Openstack Platform 13 Queens
- Red Hat Red Hat Openstack Platform 16.2: before 1:20.6.2-2.20260317135026.8a24acd.el8ost (fixed in 1:20.6.2-2.20260317135026.8a24acd.el8ost)
- Red Hat Red Hat Openstack Platform 17.1
- Red Hat Red Hat Openstack Platform 17.1 For Rhel 9: before 0:1.2.0-1.4.el9ost (fixed in 0:1.2.0-1.4.el9ost); before 0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost (fixed in 0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost); before 0:0.2.1-6.el9ost (fixed in 0:0.2.1-6.el9ost); before 0:24.3.4.2-7.el9ost (fixed in 0:24.3.4.2-7.el9ost); before 0:3.4.26-9.6.el9ost (fixed in 0:3.4.26-9.6.el9ost); before 0:17.1-20260901.1.el9ost (fixed in 0:17.1-20260901.1.el9ost); …
- Red Hat Red Hat Openstack Platform 18.0
- Red Hat Red Hat Openstack Services On Openshift 18.0: before 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost (fixed in 1:27.5.2-18.0.20260312122217.c1c6d67.el9ost)
Published 2026-02-18. Last modified 2026-09-11.