Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-17376
Python vulnerability analysis and mitigation

Overview

CVE-2020-17376 is a vulnerability discovered in OpenStack Nova's live migration feature, affecting versions <19.3.1, >=20.0.0 <20.3.1, and 21.0.0. The vulnerability was reported by Tadayoshi Hosoya (NEC) and Lee Yarwood (Red Hat) and disclosed on August 25, 2020. The issue affects the Guest.migrate functionality in virt/libvirt/guest.py in OpenStack Nova (OpenStack Advisory).

Technical details

The vulnerability occurs when performing a soft reboot of an instance that has previously undergone live migration. The issue stems from Nova not providing VIR_MIGRATE_PARAM_PERSIST_XML during migration, resulting in the original source domain's persistent configuration being used instead of the destination configuration. This affects deployments allowing host-based connections for instance root and ephemeral devices (OSS Security).

Impact

When exploited, this vulnerability allows users to gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source. This can include block devices that map to different Cinder volumes at the destination than at the source, potentially leading to unauthorized access to data or data corruption (OpenStack Advisory).

Exploitability

The vulnerability requires specific conditions to be exploited: the instance must have undergone live migration (typically an admin-only operation), and the user must have permission to perform soft reboots. The risk is significantly increased in non-default configurations where untrusted users are allowed to initiate live migrations (OpenStack Advisory).

Mitigation and workarounds

Until patches can be applied, administrators are recommended to disable soft reboots in policy (only allowing hard reboots) and consider temporarily disabling live migrations for untrusted users. Patches have been provided for multiple OpenStack versions including Pike, Queens, Rocky, Stein, Train, Ussuri, and Victoria (OpenStack Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61599HIGH8.8
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61596HIGH7.1
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61588MEDIUM6.5
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61589MEDIUM6.3
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61597MEDIUM5.1
  • Python logoPython
  • djust
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management