- What: A vulnerability in Nova allows an attacker to destroy data on the host system due to incorrect qemu-img call without format restriction when resizing disks.
- Impact: An attacker could potentially destroy data on the host system.
- Affected: Nova OpenStack Compute cloud infrastructure.
- Patch: Update system to the specified package versions for Ubuntu 25.10, 24.04 LTS, and 22.04 LTS.
Ubuntu Security Notices USN-8049-1 USN-8049-1: Nova vulnerability Publication date 17 February 2026 Overview Nova could be made to destroy data. Releases 25.10 24.04 LTS 22.04 LTS Packages nova - OpenStack Compute cloud infrastructure Details Dan Smith discovered that Nova incorrectly called qemu-img without a format restriction when resizing disks. An attacker could possibly use this issue to destroy data on the host system. Dan Smith discovered that Nova incorrectly called qemu-img without a format restriction when resizing disks. An attacker could possibly use this issue to destroy data on the host system. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 25.10 questing nova-common – 3:32.0.0-0ubuntu1.1 python3-nova – 3:32.0.0-0ubuntu1.1 24.04 LTS noble nova-common – 3:29.2.0-0ubuntu1.3 python3-nova – 3:29.2.0-0ubuntu1.3 22.04 LTS jammy nova-common – 3:25.2.1-0ubuntu2.10 python3-nova – 3:25.2.1-0ubuntu2.10 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-24708 CVE-2026-24708