{"id":"CVE-2016-2140","aliases":["GHSA-49jv-37hm-6gfp","PYSEC-2026-864"],"url":"https://o3.security/vulnerability/CVE-2016-2140","summary":"OpenStack Nova host data access through resize/migration","details":"The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.","published":"2016-04-12T14:59:10.120Z","modified":"2026-07-08T12:53:49.083502Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nova","fixedVersion":"12.0.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/03/08/6"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/84277"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/nova/+bug/1548450"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2016-007.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:53:49.083502Z"}}