Back

MEDIUM

openstack-neutron: iptables not active after update

Published Jul 26, 2018

Description

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

Affected products

Remediation

Red Hat mitigation

To determine whether your system is impacted, run: $ sudo sysctl net.bridge.bridge-nf-call-ip6tables $ sudo sysctl net.bridge.bridge-nf-call-iptables Both should be set to 1 To reset security groups to '1': 1. Apply the following configuration modification: $ sudo sed -i.back -e 's/reapply_sysctl = 0/reapply_sysctl = 1/' /etc/tuned/tuned-main.conf 2. Ensure the modification was successful: $ grep reapply_sysctl /etc/tuned/tuned-main.conf should be "reapply_sysctl = 1" 3. Check whether tuned is running: $ sudo systemctl status tuned 4. Restart tuned to apply the new configuration: $ sudo systemctl restart tuned 5. Recheck your security groups and the status of 'reapply_sysctl'.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 26, 2018
Updated Aug 5, 2024
Reserved Apr 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 8, 2017
GHSA-HVXR-2FVV-C3WQ