openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova

zetlyn/cve-redhat vulnerability cve CVE-2026-24708 known 2026-02-17

https://access.redhat.com/security/cve/CVE-2026-24708

Properties

cvss7.1
receipt
Source
Red Hat
Its words
7.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-24708",
  "CWE": "CWE-73",
  "advisories": [
    "RHSA-2026:66401",
    "RHSA-2026:54757",
    "RHSA-2026:7884"
  ],
  "affected_packages": [
    "python-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost",
    "ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost",
    "openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost",
    "python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost",
    "erlang-0:24.3.4.2-7.el9ost",
    "rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost",
    "rhosp-director-images-0:17.1-20260901.1.el9ost",
    "python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost",
    "rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost",
    "python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost",
    "openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost",
    "rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost",
    "openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost",
    "openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost",
    "etcd-0:3.4.26-9.6.el9ost",
    "python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost",
    "rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost",
    "os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost",
    "rhosp-director-images-minimal-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost",
    "collectd-sensubility-0:0.2.1-6.el9ost",
    "rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost",
    "ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost",
    "python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost",
    "python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost",
    "puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost",
    "openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost",
    "rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost",
    "octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost",
    "puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost",
    "rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost",
    "octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost",
    "tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost",
    "rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost"
  ],
  "bugzilla": "2430312",
  "bugzilla_description": "openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-02-17T15:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-24708.json",
  "severity": "important"
}
cweCWE-73
receipt
Source
Red Hat
Its words
CWE-73
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-24708",
  "CWE": "CWE-73",
  "advisories": [
    "RHSA-2026:66401",
    "RHSA-2026:54757",
    "RHSA-2026:7884"
  ],
  "affected_packages": [
    "python-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost",
    "ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost",
    "openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost",
    "python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost",
    "erlang-0:24.3.4.2-7.el9ost",
    "rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost",
    "rhosp-director-images-0:17.1-20260901.1.el9ost",
    "python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost",
    "rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost",
    "python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost",
    "openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost",
    "rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost",
    "openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost",
    "openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost",
    "etcd-0:3.4.26-9.6.el9ost",
    "python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost",
    "rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost",
    "os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost",
    "rhosp-director-images-minimal-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost",
    "collectd-sensubility-0:0.2.1-6.el9ost",
    "rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost",
    "ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost",
    "python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost",
    "python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost",
    "puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost",
    "openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost",
    "rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost",
    "octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost",
    "puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost",
    "rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost",
    "octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost",
    "tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost",
    "rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost"
  ],
  "bugzilla": "2430312",
  "bugzilla_description": "openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-02-17T15:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-24708.json",
  "severity": "important"
}
packagespython-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost, ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost, openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost, python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost, erlang-0:24.3.4.2-7.el9ost, rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost, rhosp-director-images-0:17.1-20260901.1.el9ost, python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost, rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost, openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost, python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost, openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost, rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost, openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost, openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost, etcd-0:3.4.26-9.6.el9ost, python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost, rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost, openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost, os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost, rhosp-director-images-minimal-0:17.1-20260901.1.el9ost, openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost, collectd-sensubility-0:0.2.1-6.el9ost, rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost, ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost, python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost, python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost, puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost, openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost, rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost, octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost, puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost, rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost, openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost, octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost, tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost, rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost
receipt
Source
Red Hat
Its words
python-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost, ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost, openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost, python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost, erlang-0:24.3.4.2-7.el9ost, rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost, rhosp-director-images-0:17.1-20260901.1.el9ost, python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost, rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost, openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost, python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost, openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost, rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost, openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost, openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost, etcd-0:3.4.26-9.6.el9ost, python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost, rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost, openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost, os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost, rhosp-director-images-minimal-0:17.1-20260901.1.el9ost, openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost, collectd-sensubility-0:0.2.1-6.el9ost, rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost, ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost, python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost, python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost, puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost, openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost, rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost, octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost, openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost, puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost, rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost, openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost, octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost, tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost, rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-24708",
  "CWE": "CWE-73",
  "advisories": [
    "RHSA-2026:66401",
    "RHSA-2026:54757",
    "RHSA-2026:7884"
  ],
  "affected_packages": [
    "python-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost",
    "ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost",
    "openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost",
    "python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost",
    "erlang-0:24.3.4.2-7.el9ost",
    "rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost",
    "rhosp-director-images-0:17.1-20260901.1.el9ost",
    "python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost",
    "rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost",
    "python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost",
    "openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost",
    "rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost",
    "openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost",
    "openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost",
    "etcd-0:3.4.26-9.6.el9ost",
    "python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost",
    "rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost",
    "os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost",
    "rhosp-director-images-minimal-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost",
    "collectd-sensubility-0:0.2.1-6.el9ost",
    "rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost",
    "ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost",
    "python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost",
    "python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost",
    "puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost",
    "openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost",
    "rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost",
    "octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost",
    "puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost",
    "rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost",
    "octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost",
    "tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost",
    "rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost"
  ],
  "bugzilla": "2430312",
  "bugzilla_description": "openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-02-17T15:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-24708.json",
  "severity": "important"
}
severityimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-24708",
  "CWE": "CWE-73",
  "advisories": [
    "RHSA-2026:66401",
    "RHSA-2026:54757",
    "RHSA-2026:7884"
  ],
  "affected_packages": [
    "python-ovsdbapp-0:1.9.4-17.1.20260304101059.65d02f0.el9ost",
    "ansible-collections-openstack-0:1.9.1-17.1.20260318160829.0e9a6f2.el9ost",
    "openstack-neutron-1:18.6.1-17.1.20260810120959.85ff760.el9ost",
    "python-django-horizon-1:19.4.1-17.1.20260630130603.9b1a13e.el9ost",
    "erlang-0:24.3.4.2-7.el9ost",
    "rhosp-director-images-uefi-fips-x86_64-0:17.1-20260901.1.el9ost",
    "rhosp-director-images-0:17.1-20260901.1.el9ost",
    "python-os-brick-0:4.3.4-17.1.20260324150947.cf69f92.el9ost",
    "rhosp-director-images-minimal-fips-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:23.2.3-17.1.20260810140853.2ace99d.el9ost",
    "python-glance-store-0:2.5.1-17.1.20260225150839.5f1cee6.el9ost",
    "openstack-ironic-python-agent-0:7.1.1-17.1.20260803104219.0211fa9.el9ost",
    "rhosp-director-images-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:20.6.2-2.20260317135026.8a24acd.el8ost",
    "openstack-swift-0:2.27.1-17.1.20260806131309.16dbcae.el9ost",
    "openstack-heat-1:16.1.1-17.1.20260713101101.edc6d60.el9ost",
    "etcd-0:3.4.26-9.6.el9ost",
    "python-oslo-messaging-0:12.7.3-17.1.20260701150916.5d6fd1a.el9ost",
    "rhosp-director-images-multirhel-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-cinder-1:18.2.2-17.1.20260702111621.f6b44fc.el9ost",
    "os-net-config-0:14.2.1-17.1.20260803103231.61d7bd7.el9ost",
    "rhosp-director-images-minimal-0:17.1-20260901.1.el9ost",
    "openstack-nova-1:27.5.2-18.0.20260312122217.c1c6d67.el9ost",
    "collectd-sensubility-0:0.2.1-6.el9ost",
    "rhosp-director-images-ipa-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-tripleo-heat-templates-0:14.3.1-17.1.20260803105013.e7c7ce3.el9ost",
    "ansible-collection-ansible-posix-0:1.2.0-1.4.el9ost",
    "python-cinder-tests-tempest-0:1.8.0-17.1.20260114160833.0e94611.el9ost",
    "python-oslo-serialization-0:4.1.1-17.1.20260326121047.bbe5d5a.el9ost",
    "puppet-rabbitmq-0:11.0.1-17.1.20260306080955.63fee2c.el9ost",
    "openstack-ironic-1:17.1.1-17.1.20260721220909.c31db88.el9ost",
    "rhosp-director-images-ipa-x86_64-0:17.1-20260901.1.el9ost",
    "octavia-amphora-image-fips-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-keystone-1:19.0.2-17.1.20260630150819.54dd95d.el9ost",
    "puppet-tripleo-0:14.2.3-17.1.20260206090839.40278e1.el9ost",
    "rhosp-director-images-x86_64-0:17.1-20260901.1.el9ost",
    "openstack-selinux-0:0.8.37-17.1.20260107141051.05dd1b2.el9ost",
    "octavia-amphora-image-x86_64-0:17.1-20260901.1.el9ost",
    "tripleo-ansible-0:3.3.1-17.1.20260603190918.8debef3.el9ost",
    "rhosp-director-images-uefi-x86_64-0:17.1-20260901.1.el9ost"
  ],
  "bugzilla": "2430312",
  "bugzilla_description": "openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-02-17T15:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-24708.json",
  "severity": "important"
}

Text

openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova