Vulnerability record · CVE-2018-1062 · published 6 March 2018
CVE-2018-1062: Redhat ovirt-engine vulnerability
Redhat · Ovirt Engine
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.
Description
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103433 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHBA-2018:0135 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1549944 | Issue TrackingThird Party Advisory |
| https://gerrit.ovirt.org/#/c/84861/ | Vendor Advisory |
| https://gerrit.ovirt.org/#/c/84875/ | Vendor Advisory |
| http://www.securityfocus.com/bid/103433 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHBA-2018:0135 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1549944 | Issue TrackingThird Party Advisory |
| https://gerrit.ovirt.org/#/c/84861/ | Vendor Advisory |
| https://gerrit.ovirt.org/#/c/84875/ | Vendor Advisory |
Track CVE-2018-1062 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1062), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.