Jeremy Stanley <jeremy> reports: Chris Behrens with Rackspace and Vangelis Tasoulas reported a set of vulnerabilities in OpenStack Nova. When migrating or resizing an instance, including live migration, existing security groups may not be reapplied after the operation completes. This can lead to unintentional network exposure for virtual machines. Only setups using the XenAPI backend are affected.
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1026175]
External References: https://launchpad.net/bugs/1073306 https://launchpad.net/bugs/1202266
Upstream fixes: https://review.openstack.org/52987 https://review.openstack.org/52991
Created attachment 823795 [details] cve-2013-4497-stable-grizzly-a.patch
Created attachment 823796 [details] cve-2013-4497-stable-grizzly-b.patch
We explicitly don't support this functionality but we do provide it, I think fixing it in the next z stream release would be fine.
openstack-nova-2013.2.1-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
openstack-nova-2013.1.5-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2014:0366 https://rhn.redhat.com/errata/RHSA-2014-0366.html