USN-8049-1: Nova vulnerability

Publication date

17 February 2026

Overview

Nova could be made to destroy data.


Packages

  • nova - OpenStack Compute cloud infrastructure

Details

Dan Smith discovered that Nova incorrectly called qemu-img without a format
restriction when resizing disks. An attacker could possibly use this issue
to destroy data on the host system.

Dan Smith discovered that Nova incorrectly called qemu-img without a format
restriction when resizing disks. An attacker could possibly use this issue
to destroy data on the host system.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
25.10 questing nova-common –  3:32.0.0-0ubuntu1.1
python3-nova –  3:32.0.0-0ubuntu1.1
24.04 LTS noble nova-common –  3:29.2.0-0ubuntu1.3
python3-nova –  3:29.2.0-0ubuntu1.3
22.04 LTS jammy nova-common –  3:25.2.1-0ubuntu2.10
python3-nova –  3:25.2.1-0ubuntu2.10

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›