CVE Tools

Description

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.

In plain language

AI Worth attention

OpenStack Nova has a high-impact issue in versions before 30.2.2, 31.2.1, and 32.1.1 where a carefully crafted disk image header and a resize operation can lead to data loss on the compute host; most small businesses only need to worry if you run OpenStack Nova and your setup uses the Flat image backend.

Executive summary

CVE-2026-24708 is an OpenStack Nova vulnerability in the Flat image backend where an attacker can supply a malicious QCOW header on a root or ephemeral disk and then trigger a resize, causing Nova to invoke qemu-img without the expected format restriction and perform an unsafe image resize operation that can destroy host data (affected compute nodes commonly run with use_cow_images=False).

If affected, business impact
Host data destructionCompute service disruptionRansomware-like impactLoss of tenant workloads

What to do now

  1. Check which OpenStack Nova version you run (look for the Nova release/build in your OpenStack deployment).
  2. Verify whether your compute nodes use the Flat image backend (commonly indicated by use_cow_images=False or equivalent Flat backend configuration).
  3. Upgrade OpenStack Nova to a fixed version: 30.2.2, 31.2.1, or 32.1.1 (whichever matches your branch).
  4. After upgrading, retest your normal resize workflow in a non-production environment to confirm resize operations behave as expected.
Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:LUI:NS:CC:NI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:NConfidentiality
None
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

OpenStack
oss-project·USaka openstack foundation
PyPI
package-ecosystem

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

References

and 9 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-24708 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store