Vulnerabilities > CVE-2017-7543

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
openstack
redhat

Summary

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

Redhat

advisories
  • rhsa
    idRHSA-2017:2447
  • rhsa
    idRHSA-2017:2448
  • rhsa
    idRHSA-2017:2449
  • rhsa
    idRHSA-2017:2450
  • rhsa
    idRHSA-2017:2451
  • rhsa
    idRHSA-2017:2452
rpms
  • openstack-neutron-1:8.3.0-11.1.el7ost
  • openstack-neutron-bgp-dragent-1:8.3.0-11.1.el7ost
  • openstack-neutron-common-1:8.3.0-11.1.el7ost
  • openstack-neutron-linuxbridge-1:8.3.0-11.1.el7ost
  • openstack-neutron-macvtap-agent-1:8.3.0-11.1.el7ost
  • openstack-neutron-metering-agent-1:8.3.0-11.1.el7ost
  • openstack-neutron-ml2-1:8.3.0-11.1.el7ost
  • openstack-neutron-openvswitch-1:8.3.0-11.1.el7ost
  • openstack-neutron-rpc-server-1:8.3.0-11.1.el7ost
  • openstack-neutron-sriov-nic-agent-1:8.3.0-11.1.el7ost
  • python-neutron-1:8.3.0-11.1.el7ost
  • python-neutron-tests-1:8.3.0-11.1.el7ost
  • openstack-neutron-1:9.3.1-2.1.el7ost
  • openstack-neutron-common-1:9.3.1-2.1.el7ost
  • openstack-neutron-linuxbridge-1:9.3.1-2.1.el7ost
  • openstack-neutron-macvtap-agent-1:9.3.1-2.1.el7ost
  • openstack-neutron-metering-agent-1:9.3.1-2.1.el7ost
  • openstack-neutron-ml2-1:9.3.1-2.1.el7ost
  • openstack-neutron-openvswitch-1:9.3.1-2.1.el7ost
  • openstack-neutron-rpc-server-1:9.3.1-2.1.el7ost
  • openstack-neutron-sriov-nic-agent-1:9.3.1-2.1.el7ost
  • python-neutron-1:9.3.1-2.1.el7ost
  • python-neutron-tests-1:9.3.1-2.1.el7ost
  • openstack-neutron-1:10.0.2-1.1.el7ost
  • openstack-neutron-common-1:10.0.2-1.1.el7ost
  • openstack-neutron-linuxbridge-1:10.0.2-1.1.el7ost
  • openstack-neutron-macvtap-agent-1:10.0.2-1.1.el7ost
  • openstack-neutron-metering-agent-1:10.0.2-1.1.el7ost
  • openstack-neutron-ml2-1:10.0.2-1.1.el7ost
  • openstack-neutron-openvswitch-1:10.0.2-1.1.el7ost
  • openstack-neutron-rpc-server-1:10.0.2-1.1.el7ost
  • openstack-neutron-sriov-nic-agent-1:10.0.2-1.1.el7ost
  • python-neutron-1:10.0.2-1.1.el7ost
  • python-neutron-tests-1:10.0.2-1.1.el7ost
  • openstack-neutron-0:2015.1.4-16.1.el7ost
  • openstack-neutron-bigswitch-0:2015.1.4-16.1.el7ost
  • openstack-neutron-brocade-0:2015.1.4-16.1.el7ost
  • openstack-neutron-cisco-0:2015.1.4-16.1.el7ost
  • openstack-neutron-common-0:2015.1.4-16.1.el7ost
  • openstack-neutron-embrane-0:2015.1.4-16.1.el7ost
  • openstack-neutron-ibm-0:2015.1.4-16.1.el7ost
  • openstack-neutron-linuxbridge-0:2015.1.4-16.1.el7ost
  • openstack-neutron-mellanox-0:2015.1.4-16.1.el7ost
  • openstack-neutron-metaplugin-0:2015.1.4-16.1.el7ost
  • openstack-neutron-metering-agent-0:2015.1.4-16.1.el7ost
  • openstack-neutron-midonet-0:2015.1.4-16.1.el7ost
  • openstack-neutron-ml2-0:2015.1.4-16.1.el7ost
  • openstack-neutron-nec-0:2015.1.4-16.1.el7ost
  • openstack-neutron-nuage-0:2015.1.4-16.1.el7ost
  • openstack-neutron-ofagent-0:2015.1.4-16.1.el7ost
  • openstack-neutron-oneconvergence-nvsd-0:2015.1.4-16.1.el7ost
  • openstack-neutron-opencontrail-0:2015.1.4-16.1.el7ost
  • openstack-neutron-openvswitch-0:2015.1.4-16.1.el7ost
  • openstack-neutron-ovsvapp-0:2015.1.4-16.1.el7ost
  • openstack-neutron-plumgrid-0:2015.1.4-16.1.el7ost
  • openstack-neutron-sriov-nic-agent-0:2015.1.4-16.1.el7ost
  • openstack-neutron-vmware-0:2015.1.4-16.1.el7ost
  • python-neutron-0:2015.1.4-16.1.el7ost
  • python-neutron-tests-0:2015.1.4-16.1.el7ost
  • openstack-neutron-1:7.2.0-12.1.el7ost
  • openstack-neutron-bigswitch-1:7.2.0-12.1.el7ost
  • openstack-neutron-brocade-1:7.2.0-12.1.el7ost
  • openstack-neutron-cisco-1:7.2.0-12.1.el7ost
  • openstack-neutron-common-1:7.2.0-12.1.el7ost
  • openstack-neutron-dev-server-1:7.2.0-12.1.el7ost
  • openstack-neutron-embrane-1:7.2.0-12.1.el7ost
  • openstack-neutron-linuxbridge-1:7.2.0-12.1.el7ost
  • openstack-neutron-mellanox-1:7.2.0-12.1.el7ost
  • openstack-neutron-metering-agent-1:7.2.0-12.1.el7ost
  • openstack-neutron-ml2-1:7.2.0-12.1.el7ost
  • openstack-neutron-nuage-1:7.2.0-12.1.el7ost
  • openstack-neutron-ofagent-1:7.2.0-12.1.el7ost
  • openstack-neutron-oneconvergence-nvsd-1:7.2.0-12.1.el7ost
  • openstack-neutron-opencontrail-1:7.2.0-12.1.el7ost
  • openstack-neutron-openvswitch-1:7.2.0-12.1.el7ost
  • openstack-neutron-ovsvapp-1:7.2.0-12.1.el7ost
  • openstack-neutron-rpc-server-1:7.2.0-12.1.el7ost
  • openstack-neutron-sriov-nic-agent-1:7.2.0-12.1.el7ost
  • python-neutron-1:7.2.0-12.1.el7ost
  • python-neutron-tests-1:7.2.0-12.1.el7ost
  • openstack-neutron-0:2014.2.3-42.el7ost
  • openstack-neutron-bigswitch-0:2014.2.3-42.el7ost
  • openstack-neutron-brocade-0:2014.2.3-42.el7ost
  • openstack-neutron-cisco-0:2014.2.3-42.el7ost
  • openstack-neutron-common-0:2014.2.3-42.el7ost
  • openstack-neutron-embrane-0:2014.2.3-42.el7ost
  • openstack-neutron-hyperv-0:2014.2.3-42.el7ost
  • openstack-neutron-ibm-0:2014.2.3-42.el7ost
  • openstack-neutron-linuxbridge-0:2014.2.3-42.el7ost
  • openstack-neutron-mellanox-0:2014.2.3-42.el7ost
  • openstack-neutron-metaplugin-0:2014.2.3-42.el7ost
  • openstack-neutron-metering-agent-0:2014.2.3-42.el7ost
  • openstack-neutron-midonet-0:2014.2.3-42.el7ost
  • openstack-neutron-ml2-0:2014.2.3-42.el7ost
  • openstack-neutron-nec-0:2014.2.3-42.el7ost
  • openstack-neutron-nuage-0:2014.2.3-42.el7ost
  • openstack-neutron-ofagent-0:2014.2.3-42.el7ost
  • openstack-neutron-oneconvergence-nvsd-0:2014.2.3-42.el7ost
  • openstack-neutron-opencontrail-0:2014.2.3-42.el7ost
  • openstack-neutron-openvswitch-0:2014.2.3-42.el7ost
  • openstack-neutron-plumgrid-0:2014.2.3-42.el7ost
  • openstack-neutron-ryu-0:2014.2.3-42.el7ost
  • openstack-neutron-sriov-nic-agent-0:2014.2.3-42.el7ost
  • openstack-neutron-vmware-0:2014.2.3-42.el7ost
  • openstack-neutron-vpn-agent-0:2014.2.3-42.el7ost
  • python-neutron-0:2014.2.3-42.el7ost