Security vulnerability with SR-IOV ports
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned | ||
neutron |
New
|
Undecided
|
Unassigned |
Bug Description
As explain in http://
The attack is described as hard to detect, easy to implement and absolutely efficient (throughput drops to 0).
A VF of a SR-IOV virtualized NIC can be assigned via pci aliases or with neutron ports.
I suppose with a VF assigned via a nova pci-passthrough these PAUSE commands would block the network. Would it be the case as well using the neutron port method ?
I don't have enough knowledge on neutron's functioning to see if these threats are serious or not, and I do not have the set up to test this myself.
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.