[SRU] [OSSA-2019-002] Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Fix Released
|
Critical
|
Gage Hugo | ||
Ubuntu Cloud Archive |
Fix Released
|
Critical
|
Corey Bryant | ||
Pike |
Fix Released
|
Critical
|
Corey Bryant | ||
Queens |
Fix Committed
|
Critical
|
Corey Bryant | ||
Rocky |
Fix Committed
|
Critical
|
Corey Bryant | ||
Stein |
Fix Released
|
Critical
|
Corey Bryant | ||
neutron |
Fix Released
|
Critical
|
IWAMOTO Toshihiro | ||
neutron (Ubuntu) |
Fix Released
|
Critical
|
Corey Bryant | ||
Bionic |
Fix Released
|
Critical
|
Corey Bryant | ||
Cosmic |
Fix Released
|
Critical
|
Corey Bryant | ||
Disco |
Fix Released
|
Critical
|
Corey Bryant |
Bug Description
It appears that we have found that neutron-
Those are the broken security rules: https:/
Here is the log when we discovered the issue: https:/
Ubuntu SRU Details
------------------
[Impact]
Neutron openvswitch agent crashes due to creation of two security groups that both use the same remote security group, where the first group doesn't define a port range and the second one does (one is a subset of the other; specifying no port range is the same as a full port range).
[Test case]
See comment #18 below.
[Regression Potential]
The fix is fairly minimal and has landed upstream in master branch. It has therefore passed all unit and function tests that get run in the upstream gate and has been reviewed by upstream neutron core reviewers. This all helps to minimize the regression potential.
description: | updated |
tags: | added: uosci |
information type: | Private Security → Private |
information type: | Private → Private Security |
Changed in neutron (Ubuntu): | |
status: | New → Triaged |
importance: | Undecided → Critical |
Changed in neutron: | |
assignee: | Brian Haley (brian-haley) → IWAMOTO Toshihiro (iwamoto) |
summary: |
- Unable to install new flows on compute nodes when having broken security - group rules + [SRU] Unable to install new flows on compute nodes when having broken + security group rules |
description: | updated |
Changed in neutron (Ubuntu Bionic): | |
assignee: | nobody → Corey Bryant (corey.bryant) |
Changed in neutron (Ubuntu Cosmic): | |
assignee: | nobody → Corey Bryant (corey.bryant) |
Changed in neutron (Ubuntu Disco): | |
assignee: | nobody → Corey Bryant (corey.bryant) |
status: | Triaged → In Progress |
Changed in neutron (Ubuntu Cosmic): | |
status: | Triaged → In Progress |
Changed in neutron (Ubuntu Bionic): | |
status: | Triaged → In Progress |
Changed in cloud-archive: | |
status: | In Progress → Fix Committed |
Changed in neutron (Ubuntu Disco): | |
status: | In Progress → Fix Committed |
summary: |
[SRU] Unable to install new flows on compute nodes when having broken - security group rules + security group rules (CVE-2019-10876) |
Changed in ossa: | |
status: | Confirmed → Fix Released |
summary: |
- [SRU] Unable to install new flows on compute nodes when having broken - security group rules (CVE-2019-10876) + [SRU] [OSSA-2019-002] Unable to install new flows on compute nodes when + having broken security group rules (CVE-2019-10876) |
tags: |
added: verification-queens-done removed: verification-queens-needed |
tags: | removed: pike-backport-potential queens-backport-potential rocky-backport-potential |
It's affecting neutron- openvswitch- agent 2:12.0. 5-0ubuntu1~ cloud0