Unrated severityNVD Advisory· Published Mar 6, 2018· Updated Sep 17, 2024
CVE-2018-1062
CVE-2018-1062
Description
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- access.redhat.com/errata/RHBA-2018:0135mitrevendor-advisoryx_refsource_REDHAT
- www.securityfocus.com/bid/103433mitrevdb-entryx_refsource_BID
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- gerrit.ovirt.orgmitrex_refsource_CONFIRM
- gerrit.ovirt.orgmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.