OpenStack Nova calls qemu-img without format restrictions for resize
High severity
GitHub Reviewed
Published
Feb 18, 2026
to the GitHub Advisory Database
•
Updated Feb 21, 2026
Package
Affected versions
>= 32.0.0.0rc1, <= 32.1.0
>= 31.0.0.0rc1, <= 31.2.0
<= 30.2.1
Patched versions
None
Description
Published by the National Vulnerability Database
Feb 18, 2026
Published to the GitHub Advisory Database
Feb 18, 2026
Reviewed
Feb 19, 2026
Last updated
Feb 21, 2026
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
References