[OSSA 2014-019] IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167)
Bug #1309195 reported by
Baodong (Robert) Li
This bug affects 3 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Fix Released
|
High
|
Tristan Cacqueray | ||
neutron |
Fix Released
|
Critical
|
Baodong (Robert) Li | ||
Havana |
Fix Released
|
Critical
|
Aaron Rosen | ||
Icehouse |
Fix Released
|
Critical
|
Aaron Rosen |
Bug Description
SNAT rules with IPv6 prefixes are added into the NAT table, which causes failure with the call to iptables-restore:
Stderr: "iptables-restore v1.4.18: invalid mask `64' specified\nError occurred at line: 22\nTry `iptables-restore -h' or 'iptables-restore --help' for more information.\n"
CVE References
Changed in neutron: | |
assignee: | nobody → Baodong (Robert) Li (baoli) |
tags: | added: ipv6 |
Changed in neutron: | |
importance: | Undecided → Critical |
Changed in ossa: | |
status: | New → Confirmed |
tags: | added: icehouse-backport-potential |
Changed in ossa: | |
importance: | Undecided → High |
Changed in ossa: | |
assignee: | nobody → Tristan Cacqueray (tristan-cacqueray) |
tags: | removed: icehouse-backport-potential in-stable-havana in-stable-icehouse |
Changed in ossa: | |
status: | Confirmed → Triaged |
Changed in neutron: | |
milestone: | none → juno-1 |
Changed in neutron: | |
status: | Fix Committed → Fix Released |
summary: |
- IPv6 prefix shouldn't be added in the NAT table + IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167) |
summary: |
- IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167) + [OSSA 2014-019] IPv6 prefix shouldn't be added in the NAT table + (CVE-2014-4167) |
Changed in ossa: | |
status: | Triaged → Fix Committed |
Changed in ossa: | |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | juno-1 → 2014.2 |
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/88584
Review: https:/