CVE-2023-2088
Linux Debian vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2023-2088) was discovered in OpenStack due to an inconsistency between Cinder and Nova components. The vulnerability was disclosed on May 10, 2023, affecting multiple OpenStack components including Cinder, Nova, Glance_store, and Os-brick across various versions. This flaw allows unauthorized access to volumes when an iSCSI or FC connection from a host is severed due to a volume being unmapped on the storage system and the device is later reused for another volume on the same host (OpenStack Advisory).

Technical details

The vulnerability manifests through two scenarios: 1) An accidental case where network connectivity issues during volume detach operations cause OpenStack to fail in proper cleanup, leading to wrong multipath device selection, and 2) An intentional case where a regular user can create an instance with a volume and delete the volume attachment directly in Cinder without Nova's knowledge, allowing unauthorized access when the SCSI plumbing reconnects. The issue specifically affects deployments using iSCSI or FC transport protocols, while other protocols such as RBD/Ceph, NFS, and NVMe-oF are not affected (Red Hat Solution).

Impact

The vulnerability's highest impact is to data confidentiality, as it can lead to unauthorized access to volume data. When exploited, an attacker could gain access to volumes belonging to other users, potentially exposing sensitive information or causing data leaks. The issue is particularly severe as it affects both accidental scenarios and intentional exploitation attempts (OpenStack Advisory, Red Hat Solution).

Mitigation and workarounds

The fix requires multiple components to be updated and configured properly: 1) Implementation of force option for fibre channel in os-brick, 2) Nova must call os-brick with force option when disconnecting volumes, 3) Cinder must distinguish between safe and unsafe attachment delete requests, 4) Nova must be configured to send service tokens to Cinder. Additionally, configuration changes are required in both Nova and Cinder to implement service token authentication (OpenStack Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33229HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33228HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-15281N/AN/A
  • WolfiWolfi
  • glibc-langpack-anp
NoYesJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management