{"id":"CVE-2016-2140","aliases":["GHSA-49jv-37hm-6gfp","PYSEC-2026-864"],"url":"https://o3.security/vulnerability/CVE-2016-2140","summary":"OpenStack Nova host data access through resize/migration","details":"The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.","published":"2016-04-12T14:59:10.120Z","modified":"2026-07-08T12:53:49.083502Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.02091,"percentile":0.80182,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nova","fixedVersion":"12.0.3"}],"fix":{"url":"https://github.com/openstack/nova/commit/0b194187db9da28225cb5e62be3b45aff5a1c793","label":"openstack/nova@0b19418"},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/03/08/6"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/84277"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/nova/+bug/1548450"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2016-007.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-2140"},{"type":"WEB","url":"https://github.com/openstack/nova/commit/0b194187db9da28225cb5e62be3b45aff5a1c793"},{"type":"WEB","url":"https://github.com/openstack/nova/commit/116b1210ab772c55d1ed1f715687d83877c92701"},{"type":"WEB","url":"https://github.com/openstack/nova/commit/f302bf04ab5dda89cf8ceaeed309006da90c0666"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0363"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0364"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0365"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0366"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2016-2140"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1313454"},{"type":"PACKAGE","url":"https://github.com/openstack/nova"},{"type":"WEB","url":"http://seclists.org/oss-sec/2016/q1/563"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:53:49.083502Z"}}