Back

HIGH

openstack-neutron: A router interface out of subnet IP range results in a denial of service

Published Sep 10, 2018

Description

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 10, 2018
Updated Aug 5, 2024
Reserved Jul 27, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 21, 2018
GHSA-X634-34M9-96MP