Bug 1026171 (CVE-2013-4497)

Summary: CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize
Product: [Other] Security Response Reporter: Garth Mollett <gmollett>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: akscram, alexander.sakhnov, aortega, apevec, apevec, ayoung, bfilippov, breu, chrisw, gkotton, gmollett, iheim, itamar, Jan.van.Eldik, jonathansteffan, jose.castro.leon, lhh, lpeer, markmc, mlvov, mmagr, ndipanov, p, rbryant, rhos-maint, sclewis, sdake, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-07-15 07:13:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1026172, 1026174, 1026175, 1032286    
Bug Blocks: 1023240, 1026177    
Attachments:
Description Flags
cve-2013-4497-stable-grizzly-a.patch
none
cve-2013-4497-stable-grizzly-b.patch none

Description Garth Mollett 2013-11-04 06:06:18 UTC
Jeremy Stanley <jeremy> reports:

Chris Behrens with Rackspace and Vangelis Tasoulas reported a set of
vulnerabilities in OpenStack Nova. When migrating or resizing an
instance, including live migration, existing security groups may not
be reapplied after the operation completes. This can lead to
unintentional network exposure for virtual machines. Only setups
using the XenAPI backend are affected.

Comment 2 Garth Mollett 2013-11-04 06:18:44 UTC
Created openstack-nova tracking bugs for this issue:

Affects: fedora-all [bug 1026175]

Comment 3 Garth Mollett 2013-11-04 06:33:15 UTC
External References:

https://launchpad.net/bugs/1073306
https://launchpad.net/bugs/1202266

Comment 4 Vincent Danen 2013-11-13 20:36:40 UTC
Upstream fixes:

https://review.openstack.org/52987
https://review.openstack.org/52991

Comment 5 Kurt Seifried 2013-11-14 07:44:13 UTC
Created attachment 823795 [details]
cve-2013-4497-stable-grizzly-a.patch

Comment 6 Kurt Seifried 2013-11-14 07:45:00 UTC
Created attachment 823796 [details]
cve-2013-4497-stable-grizzly-b.patch

Comment 12 Kurt Seifried 2013-11-19 19:23:36 UTC
We explicitly don't support this functionality but we do provide it, I think fixing it in the next z stream release would be fine.

Comment 14 Fedora Update System 2014-01-07 09:34:52 UTC
openstack-nova-2013.2.1-2.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 Fedora Update System 2014-04-02 09:14:05 UTC
openstack-nova-2013.1.5-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 16 errata-xmlrpc 2014-04-03 20:20:24 UTC
This issue has been addressed in following products:

  OpenStack 3 for RHEL 6

Via RHSA-2014:0366 https://rhn.redhat.com/errata/RHSA-2014-0366.html