Bug 1570203 - python-oslo-rootwrap: IpNetnsExecFilter bypass in CommandFilter function
Summary: python-oslo-rootwrap: IpNetnsExecFilter bypass in CommandFilter function
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1570204
TreeView+ depends on / blocked
 
Reported: 2018-04-20 22:13 UTC by Laura Pardo
Modified: 2021-02-17 00:25 UTC (History)
19 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-28 11:21:08 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Launchpad 1765734 0 None None None 2018-04-24 10:56:16 UTC

Description Laura Pardo 2018-04-20 22:13:17 UTC
A flaw was found in Oslo Rootwrap CommandFilter function. IpNetnsExecFilter can be bypassed when an specific filter is enabled this could allow arbitrary code execution

Comment 1 Victor Stinner 2018-04-21 08:36:00 UTC
Hum, am I supposed to do anything?

Comment 2 Joshua Padman 2018-04-27 04:19:59 UTC
Upstream have made the bug public:
https://bugs.launchpad.net/oslo.rootwrap/+bug/1765734

Comment 3 Joshua Padman 2018-04-27 04:20:06 UTC
Acknowledgments:

Name: Daniel Alvarez (Red Hat)

Comment 4 Joshua Padman 2018-05-28 11:21:08 UTC
This has been treated as a hardening issue upstream and likewise here. The issue, which is not considered a vulnerability, will be fixed as features are pulled in from upstream.


Note You need to log in before you can comment on or make changes to this bug.