Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1269119 - (CVE-2015-7713) CVE-2015-7713 openstack-nova: network security group changes are not applied to running instances
CVE-2015-7713 openstack-nova: network security group changes are not applied ...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20151005,repor...
: Security
Depends On: 1269122 1269123 1272863 1272864 1272865 1272866
Blocks: 1269121
  Show dependency treegraph
 
Reported: 2015-10-06 07:47 EDT by Martin Prpič
Modified: 2018-09-23 23:30 EDT (History)
56 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A vulnerability was discovered in the way OpenStack Compute (nova) networking handled security group updates; changes were not applied to already running VM instances. A remote attacker could use this flaw to access running VM instances.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-01-10 19:30:53 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:2673 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix advisory 2015-12-21 16:51:35 EST
Red Hat Product Errata RHSA-2015:2684 normal SHIPPED_LIVE Moderate: openstack-nova secuity and bug fix advisory 2015-12-21 18:43:27 EST
Red Hat Product Errata RHSA-2016:0013 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix advisory 2016-01-07 20:47:38 EST
Red Hat Product Errata RHSA-2016:0017 normal SHIPPED_LIVE Important: openstack-nova security advisory 2016-01-10 23:20:21 EST

  None (edit)
Description Martin Prpič 2015-10-06 07:47:48 EDT
Title: Nova network security group changes are not applied to running instances

Reporter: Sreekumar S and Suntao
Products: Nova
Affects: <=2014.2.3, >=2015.1.0, <=2015.1.1

Description:

Sreekumar S and Suntao independently reported a vulnerability in Nova network. Security group changes silently fail to be applied to already running instances, potentially resulting in instances not being protected by the security group. All Nova network setups are affected.

References:

https://launchpad.net/bugs/1491307
https://launchpad.net/bugs/1484738
http://seclists.org/oss-sec/2015/q4/41
Comment 1 Martin Prpič 2015-10-06 07:50:21 EDT
Created openstack-nova tracking bugs for this issue:

Affects: openstack-rdo [bug 1269122]
Affects: fedora-all [bug 1269123]
Comment 3 Adam Mariš 2015-10-08 04:23:25 EDT
Upstream patches:

https://review.openstack.org/222026 (Juno)
https://review.openstack.org/222023 (Kilo)
https://review.openstack.org/222022 (Liberty)
Comment 7 errata-xmlrpc 2015-12-21 12:06:28 EST
This issue has been addressed in the following products:

  OpenStack 7 For RHEL 7

Via RHSA-2015:2673 https://access.redhat.com/errata/RHSA-2015:2673
Comment 8 errata-xmlrpc 2015-12-21 13:45:13 EST
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 7

Via RHSA-2015:2684 https://rhn.redhat.com/errata/RHSA-2015-2684.html
Comment 9 errata-xmlrpc 2016-01-07 15:49:01 EST
This issue has been addressed in the following products:

  OpenStack 6 for RHEL 7

Via RHSA-2016:0013 https://rhn.redhat.com/errata/RHSA-2016-0013.html
Comment 10 errata-xmlrpc 2016-01-10 18:20:39 EST
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 6

Via RHSA-2016:0017 https://rhn.redhat.com/errata/RHSA-2016-0017.html

Note You need to log in before you can comment on or make changes to this bug.