CVE-2013-7130
Summary
| CVE | CVE-2013-7130 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-06 17:00:06 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage. |
Risk And Classification
Primary CVSS: v2.0 7.1 from [email protected]
AV:N/AC:M/Au:N/C:C/I:N/A:N
EPSS: 0.025390000 probability, percentile 0.855250000 (date 2026-05-04)
Problem Types: CWE-200 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Compute | 2012.2 | All | All | All |
| Application | Openstack | Compute | 2013.1 | All | All | All |
| Application | Openstack | Compute | 2013.1.1 | All | All | All |
| Application | Openstack | Compute | 2013.1.2 | All | All | All |
| Application | Openstack | Compute | 2013.1.3 | All | All | All |
| Application | Openstack | Grizzly | - | All | All | All |
| Application | Openstack | Havana | - | All | All | All |
| Application | Openstack | Icehouse | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 19 Update: openstack-nova-2013.1.4-6.fc19 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| osvdb.org/102416 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Security Advisory SA56450 - OpenStack Compute (Nova) Live Migration Root Disk Contents Disclosure Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Bug #1251590 “[OSSA 2014-003] Live migration can leak root disk ...” : Bugs : OpenStack Compute (nova) | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Gerrit Code Review | af854a3a-2127-422b-91ae-364da2661108 | review.openstack.org | Patch |
| oss-security - [OSSA 2014-003] Live migration can leak root disk into ephemeral storage (CVE-2013-7130) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 20 Update: openstack-nova-2013.2.1-4.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Gerrit Code Review | af854a3a-2127-422b-91ae-364da2661108 | review.openstack.org | Patch |
| USN-2247-1: OpenStack Nova vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Gerrit Code Review | af854a3a-2127-422b-91ae-364da2661108 | review.openstack.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.