CVE-2019-10876
Summary
| CVE | CVE-2019-10876 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-05 05:29:00 UTC |
| Updated | 2021-08-04 17:15:00 UTC |
| Description | An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Neutron | All | All | All | All |
| Application | Openstack | Neutron | All | All | All | All |
| Application | Redhat | Openstack | 13 | All | All | All |
| Application | Redhat | Openstack | 13.0 | All | All | All |
| Application | Redhat | Openstack | 14 | All | All | All |
| Application | Redhat | Openstack | 14.0 | All | All | All |
| Application | Redhat | Openstack | 13.0 | All | All | All |
| Application | Redhat | Openstack | 14.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Bug #1813007 “[SRU] [OSSA-2019-002] Unable to install new flows ...” : Bugs : OpenStack Security Advisory | MISC | bugs.launchpad.net | Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| oss-security - [OSSA-2019-002] neutron-openvswitch-agent: Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876) | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| OpenStack Docs: OSSA-2019-002: Overlapping security group rules prevents compute node network configuration | CONFIRM | security.openstack.org | Third Party Advisory |
| Gerrit Code Review | MISC | review.openstack.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 998090 Python (Pip) Security Update for neutron (GHSA-jr9m-v5qh-mh2j)