ISOMAN

CVE

CVE-2017-5936

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://www.openwall.com/lists/oss-security/2017/02/09/3
  2. http://www.securityfocus.com/bid/96182
  3. http://www.ubuntu.com/usn/USN-3195-1
  4. https://bugs.launchpad.net/nova-lxd/+bug/1656847
  5. https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2
  6. http://www.openwall.com/lists/oss-security/2017/02/09/3
  7. http://www.securityfocus.com/bid/96182
  8. http://www.ubuntu.com/usn/USN-3195-1
  9. https://bugs.launchpad.net/nova-lxd/+bug/1656847
  10. https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2