Bug 1269119 (CVE-2015-7713) - CVE-2015-7713 openstack-nova: network security group changes are not applied to running instances
Summary: CVE-2015-7713 openstack-nova: network security group changes are not applied ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-7713
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1269122 1269123 1272863 1272864 1272865 1272866
Blocks: 1269121
TreeView+ depends on / blocked
 
Reported: 2015-10-06 11:47 UTC by Martin Prpič
Modified: 2019-09-29 13:37 UTC (History)
56 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A vulnerability was discovered in the way OpenStack Compute (nova) networking handled security group updates; changes were not applied to already running VM instances. A remote attacker could use this flaw to access running VM instances.
Clone Of:
Environment:
Last Closed: 2016-01-11 00:30:53 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:2673 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix advisory 2015-12-21 21:51:35 UTC
Red Hat Product Errata RHSA-2015:2684 normal SHIPPED_LIVE Moderate: openstack-nova secuity and bug fix advisory 2015-12-21 23:43:27 UTC
Red Hat Product Errata RHSA-2016:0013 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix advisory 2016-01-08 01:47:38 UTC
Red Hat Product Errata RHSA-2016:0017 normal SHIPPED_LIVE Important: openstack-nova security advisory 2016-01-11 04:20:21 UTC

Description Martin Prpič 2015-10-06 11:47:48 UTC
Title: Nova network security group changes are not applied to running instances

Reporter: Sreekumar S and Suntao
Products: Nova
Affects: <=2014.2.3, >=2015.1.0, <=2015.1.1

Description:

Sreekumar S and Suntao independently reported a vulnerability in Nova network. Security group changes silently fail to be applied to already running instances, potentially resulting in instances not being protected by the security group. All Nova network setups are affected.

References:

https://launchpad.net/bugs/1491307
https://launchpad.net/bugs/1484738
http://seclists.org/oss-sec/2015/q4/41

Comment 1 Martin Prpič 2015-10-06 11:50:21 UTC
Created openstack-nova tracking bugs for this issue:

Affects: openstack-rdo [bug 1269122]
Affects: fedora-all [bug 1269123]

Comment 3 Adam Mariš 2015-10-08 08:23:25 UTC
Upstream patches:

https://review.openstack.org/222026 (Juno)
https://review.openstack.org/222023 (Kilo)
https://review.openstack.org/222022 (Liberty)

Comment 7 errata-xmlrpc 2015-12-21 17:06:28 UTC
This issue has been addressed in the following products:

  OpenStack 7 For RHEL 7

Via RHSA-2015:2673 https://access.redhat.com/errata/RHSA-2015:2673

Comment 8 errata-xmlrpc 2015-12-21 18:45:13 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 7

Via RHSA-2015:2684 https://rhn.redhat.com/errata/RHSA-2015-2684.html

Comment 9 errata-xmlrpc 2016-01-07 20:49:01 UTC
This issue has been addressed in the following products:

  OpenStack 6 for RHEL 7

Via RHSA-2016:0013 https://rhn.redhat.com/errata/RHSA-2016-0013.html

Comment 10 errata-xmlrpc 2016-01-10 23:20:39 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 6

Via RHSA-2016:0017 https://rhn.redhat.com/errata/RHSA-2016-0017.html


Note You need to log in before you can comment on or make changes to this bug.