{"api_version":"1","generated_at":"2026-07-23T06:15:27+00:00","cve":"CVE-2012-5625","urls":{"html":"https://cve.report/CVE-2012-5625","api":"https://cve.report/api/cve/CVE-2012-5625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5625"},"summary":{"title":"CVE-2012-5625","description":"OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).","state":"PUBLISHED","assigner":"redhat","published_at":"2012-12-26 22:55:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f","name":"https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Don't leak info from libvirt LVM backed instances · openstack/nova@9d2ea97 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=884293","name":"https://bugzilla.redhat.com/show_bug.cgi?id=884293","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"884293 – (CVE-2012-5625) CVE-2012-5625 OpenStack Nova: Information leak in libvirt LVM-backed instances","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354","name":"https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Don't leak info from libvirt LVM backed instances · openstack/nova@a99a802 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-1663-1","name":"http://www.ubuntu.com/usn/USN-1663-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"USN-1663-1: Nova vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/56904","name":"http://www.securityfocus.com/bid/56904","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenStack Nova CVE-2012-5625 Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://launchpad.net/nova/folsom/2012.2.2","name":"https://launchpad.net/nova/folsom/2012.2.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"2012.2.2 : Series folsom : OpenStack Compute (nova)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/12/11/5","name":"http://www.openwall.com/lists/oss-security/2012/12/11/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - [OSSA 2012-020] Information leak in libvirt LVM-backed instances\n (CVE-2012-5625)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0208.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0208.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://osvdb.org/88419","name":"http://osvdb.org/88419","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://bugs.launchpad.net/nova/+bug/1070539","name":"https://bugs.launchpad.net/nova/+bug/1070539","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug #1070539 “[OSSA 2012-020] create_lvm_image allocates dirty b...” : Bugs : OpenStack Compute (nova)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5625","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"folsom","cpe6":"2012.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5625","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"grizzly","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:14:16.142Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2013:0208","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0208.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/nova/+bug/1070539"},{"name":"USN-1663-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1663-1"},{"name":"56904","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/56904"},{"name":"88419","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/88419"},{"name":"[oss-security] 20121211 [OSSA 2012-020] Information leak in libvirt LVM-backed instances (CVE-2012-5625)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/12/11/5"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://launchpad.net/nova/folsom/2012.2.2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=884293"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-12-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-02-15T10:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2013:0208","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0208.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/nova/+bug/1070539"},{"name":"USN-1663-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1663-1"},{"name":"56904","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/56904"},{"name":"88419","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/88419"},{"name":"[oss-security] 20121211 [OSSA 2012-020] Information leak in libvirt LVM-backed instances (CVE-2012-5625)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/12/11/5"},{"tags":["x_refsource_CONFIRM"],"url":"https://launchpad.net/nova/folsom/2012.2.2"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=884293"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-5625","datePublished":"2012-12-26T22:00:00.000Z","dateReserved":"2012-10-24T00:00:00.000Z","dateUpdated":"2024-08-06T21:14:16.142Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-12-26 22:55:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:folsom:2012.2:*:*:*:*:*:*:*","matchCriteriaId":"E76B76AB-D744-4163-8615-7BA18ABB1347"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:*","matchCriteriaId":"A83ED744-9E3D-4510-B3E6-6DDE1090F0B7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5625","Ordinal":"1","Title":"CVE-2012-5625","CVE":"CVE-2012-5625","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5625","Ordinal":"1","NoteData":"OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).","Type":"Description","Title":"CVE-2012-5625"},{"CveYear":"2012","CveId":"5625","Ordinal":"2","NoteData":"2012-12-26","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5625","Ordinal":"3","NoteData":"2013-02-15","Type":"Other","Title":"Modified"}]}}}