[OSSA 2014-025] There is no quota for allowed address pair (CVE-2014-3555)
Bug #1336207 reported by
Liping Mao
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Fix Released
|
High
|
Tristan Cacqueray | ||
neutron |
Fix Released
|
Undecided
|
Liping Mao | ||
Havana |
Fix Released
|
Undecided
|
Liping Mao | ||
Icehouse |
Fix Released
|
Undecided
|
Liping Mao |
Bug Description
Hi all,
There is no quota for allowed address pair, user can create unlimited allowed address pair, in the backend, there will be at least 1 iptables rule for one allowed address pair. I tested if we use the attachment script to add about 10,000 allowed address pair. It will cost 30 sec to reflesh iptables rules in kernel... I think that bad man can use this api to attack compute nodes. This will make the compute nodes crash or very slow only if we add enough allowed address pair rules...
Thanks.
Liping Mao
CVE References
Changed in ossa: | |
status: | New → Incomplete |
Changed in neutron: | |
assignee: | nobody → Liping Mao (limao) |
Changed in ossa: | |
status: | Incomplete → Confirmed |
importance: | Undecided → High |
Changed in ossa: | |
assignee: | nobody → Tristan Cacqueray (tristan-cacqueray) |
summary: |
- There is no quota for allowed address pair + There is no quota for allowed address pair (CVE-2014-3555) |
Changed in ossa: | |
status: | Confirmed → In Progress |
Changed in ossa: | |
status: | In Progress → Fix Committed |
Changed in neutron: | |
status: | New → In Progress |
Changed in ossa: | |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | none → juno-2 |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | juno-2 → 2014.2 |
To post a comment you must log in.
This sounds similar to nova bug 1184041 (OSSA 2013-020, CVE-2013-4185). In which OpenStack release(s) did you observe this behavior?