#VU122995 Allocation of resources without limits or throttling in Openstack Nova - CVE-2026-24708
Published: February 17, 2026
Openstack Nova
Openstack
Description
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to the application calls qemu-img without format restrictions for resize. A local user can write malicious QCOW header to a root or ephemeral disk and then trigger a resize to convince Nova’s flat image backend to call qemu-img without a format restriction resulting in an unsafe image resize operation that could destroy data on the host system.