QID 997509

Date Published: 2024-02-26

QID 997509: Python (Pip) Security Update for neutron (GHSA-hvm4-mc7m-22w4)

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Github security advisory GHSA-hvm4-mc7m-22w4 for updates and patch information.
    Vendor References

    CVEs related to QID 997509

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hvm4-mc7m-22w4 neutron URL Logo github.com/advisories/GHSA-hvm4-mc7m-22w4