Activity log for bug #1813007

Date Who What changed Old value New value Message
2019-01-23 12:22:47 Diko Parvanov bug added bug
2019-01-23 12:28:30 Diko Parvanov affects neutron neutron (Ubuntu)
2019-01-23 12:36:51 Giuseppe Petralia description It appears that we have found that neutron-openvswitch-agent appears to have a bug where a security group that has two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/ It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/
2019-02-27 10:34:27 Ryan Beisner tags uosci
2019-02-27 10:34:31 Ryan Beisner bug added subscriber Ryan Beisner
2019-02-27 19:37:34 Corey Bryant information type Public Private Security
2019-02-27 19:42:34 Corey Bryant removed subscriber Ryan Beisner
2019-02-27 19:43:10 Corey Bryant information type Private Security Private
2019-02-27 19:43:21 Corey Bryant information type Private Private Security
2019-02-27 19:44:20 Corey Bryant bug added subscriber Ryan Beisner
2019-02-27 19:55:27 Ryan Beisner bug added subscriber Dean Henrichsmeyer
2019-02-27 19:55:36 Ryan Beisner bug added subscriber James Troup
2019-02-27 19:56:26 Ryan Beisner bug added subscriber Drew Freiberger
2019-02-27 19:56:32 Ryan Beisner bug added subscriber James Page
2019-02-28 12:54:56 Corey Bryant neutron (Ubuntu): status New Triaged
2019-02-28 12:55:04 Corey Bryant neutron (Ubuntu): importance Undecided Critical
2019-02-28 12:55:08 Corey Bryant bug task added neutron
2019-02-28 13:54:43 Corey Bryant attachment added juju-deployer bundle https://bugs.launchpad.net/neutron/+bug/1813007/+attachment/5242288/+files/default.yaml
2019-02-28 13:55:15 Corey Bryant attachment added neutron-openvswitch-agent.log https://bugs.launchpad.net/neutron/+bug/1813007/+attachment/5242289/+files/neutron-openvswitch-agent.log
2019-02-28 15:41:10 Corey Bryant nominated for series Ubuntu Disco
2019-02-28 15:41:10 Corey Bryant bug task added neutron (Ubuntu Disco)
2019-02-28 15:41:10 Corey Bryant nominated for series Ubuntu Xenial
2019-02-28 15:41:10 Corey Bryant bug task added neutron (Ubuntu Xenial)
2019-02-28 15:41:10 Corey Bryant nominated for series Ubuntu Cosmic
2019-02-28 15:41:10 Corey Bryant bug task added neutron (Ubuntu Cosmic)
2019-02-28 15:41:10 Corey Bryant nominated for series Ubuntu Bionic
2019-02-28 15:41:10 Corey Bryant bug task added neutron (Ubuntu Bionic)
2019-02-28 15:42:01 Corey Bryant neutron (Ubuntu Cosmic): status New Triaged
2019-02-28 15:42:04 Corey Bryant neutron (Ubuntu Bionic): status New Triaged
2019-02-28 15:42:06 Corey Bryant neutron (Ubuntu Xenial): status New Triaged
2019-02-28 15:42:10 Corey Bryant neutron (Ubuntu Cosmic): importance Undecided Critical
2019-02-28 15:42:11 Corey Bryant neutron (Ubuntu Bionic): importance Undecided Critical
2019-02-28 15:42:13 Corey Bryant neutron (Ubuntu Xenial): importance Undecided Critical
2019-02-28 15:42:20 Corey Bryant bug task added cloud-archive
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/ocata
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/ocata
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/pike
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/pike
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/mitaka
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/mitaka
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/queens
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/queens
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/stein
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/stein
2019-02-28 15:42:49 Corey Bryant nominated for series cloud-archive/rocky
2019-02-28 15:42:49 Corey Bryant bug task added cloud-archive/rocky
2019-02-28 15:43:36 Corey Bryant cloud-archive/mitaka: importance Undecided Critical
2019-02-28 15:43:36 Corey Bryant cloud-archive/mitaka: status New Triaged
2019-02-28 15:43:48 Corey Bryant cloud-archive/ocata: importance Undecided Critical
2019-02-28 15:43:48 Corey Bryant cloud-archive/ocata: status New Triaged
2019-02-28 15:43:59 Corey Bryant cloud-archive/pike: importance Undecided Critical
2019-02-28 15:43:59 Corey Bryant cloud-archive/pike: status New Triaged
2019-02-28 15:44:16 Corey Bryant cloud-archive/queens: importance Undecided Critical
2019-02-28 15:44:16 Corey Bryant cloud-archive/queens: status New Triaged
2019-02-28 15:44:30 Corey Bryant cloud-archive/rocky: importance Undecided Critical
2019-02-28 15:44:30 Corey Bryant cloud-archive/rocky: status New Triaged
2019-02-28 15:46:47 Corey Bryant cloud-archive/stein: importance Undecided Critical
2019-02-28 15:46:47 Corey Bryant cloud-archive/stein: status New Triaged
2019-02-28 15:47:08 Corey Bryant cloud-archive/pike: importance Critical Undecided
2019-02-28 15:47:08 Corey Bryant cloud-archive/pike: status Triaged New
2019-02-28 15:47:19 Corey Bryant cloud-archive/ocata: importance Critical Undecided
2019-02-28 15:47:19 Corey Bryant cloud-archive/ocata: status Triaged New
2019-02-28 15:47:29 Corey Bryant cloud-archive/mitaka: importance Critical Undecided
2019-02-28 15:47:29 Corey Bryant cloud-archive/mitaka: status Triaged New
2019-02-28 17:21:42 Corey Bryant bug task deleted cloud-archive/ocata
2019-02-28 17:21:49 Corey Bryant bug task deleted cloud-archive/mitaka
2019-02-28 17:22:00 Corey Bryant cloud-archive/pike: importance Undecided Critical
2019-02-28 17:22:00 Corey Bryant cloud-archive/pike: status New Triaged
2019-02-28 17:35:57 Gage Hugo bug task added ossa
2019-02-28 17:36:10 Gage Hugo ossa: status New Incomplete
2019-02-28 17:36:26 Gage Hugo description It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/ This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/
2019-02-28 17:37:08 Gage Hugo bug added subscriber Neutron Core Security reviewers
2019-02-28 19:19:20 Gage Hugo description This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/ It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/
2019-02-28 19:19:33 Gage Hugo information type Private Security Public Security
2019-02-28 22:12:25 James Troup bug added subscriber Tori
2019-03-01 03:13:30 Brian Haley neutron: importance Undecided Critical
2019-03-01 03:13:30 Brian Haley neutron: status New Confirmed
2019-03-01 03:13:30 Brian Haley neutron: assignee Brian Haley (brian-haley)
2019-03-01 03:24:53 OpenStack Infra neutron: status Confirmed In Progress
2019-03-08 09:38:53 OpenStack Infra neutron: assignee Brian Haley (brian-haley) IWAMOTO Toshihiro (iwamoto)
2019-03-27 02:08:58 OpenStack Infra neutron: status In Progress Fix Released
2019-03-27 11:29:39 Corey Bryant summary Unable to install new flows on compute nodes when having broken security group rules [SRU] Unable to install new flows on compute nodes when having broken security group rules
2019-03-27 12:20:34 Corey Bryant description It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/ It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present. Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/ Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/ Ubuntu SRU Details ------------------ [Impact] Neutron openvswitch agent crashes due to creation of two security groups that both use the same remote security group, where the first group doesn't define a port range and the second one does (one is a subset of the other; specifying no port range is the same as a full port range). [Test case] See comment #18 below. [Regression Potential] The fix is fairly minimal and has landed upstream in master branch. It has therefore passed all unit and function tests that get run in the upstream gate and has been reviewed by upstream neutron core reviewers. This all helps to minimize the regression potential.
2019-03-27 13:24:47 Corey Bryant bug task deleted neutron (Ubuntu Xenial)
2019-03-27 14:21:36 Corey Bryant bug added subscriber Ubuntu Stable Release Updates Team
2019-03-27 14:31:06 Corey Bryant cloud-archive/stein: assignee Corey Bryant (corey.bryant)
2019-03-27 14:31:18 Corey Bryant cloud-archive/rocky: assignee Corey Bryant (corey.bryant)
2019-03-27 14:31:44 Corey Bryant cloud-archive/queens: assignee Corey Bryant (corey.bryant)
2019-03-27 14:31:53 Corey Bryant cloud-archive/pike: assignee Corey Bryant (corey.bryant)
2019-03-27 14:32:02 Corey Bryant neutron (Ubuntu Bionic): assignee Corey Bryant (corey.bryant)
2019-03-27 14:32:12 Corey Bryant neutron (Ubuntu Cosmic): assignee Corey Bryant (corey.bryant)
2019-03-27 14:32:22 Corey Bryant neutron (Ubuntu Disco): assignee Corey Bryant (corey.bryant)
2019-03-27 14:33:21 Corey Bryant cloud-archive/stein: status Triaged In Progress
2019-03-27 14:33:32 Corey Bryant cloud-archive/rocky: status Triaged In Progress
2019-03-27 14:33:44 Corey Bryant cloud-archive/queens: status Triaged In Progress
2019-03-27 14:33:55 Corey Bryant cloud-archive/pike: status Triaged In Progress
2019-03-27 14:34:08 Corey Bryant neutron (Ubuntu Disco): status Triaged In Progress
2019-03-27 14:34:25 Corey Bryant neutron (Ubuntu Cosmic): status Triaged In Progress
2019-03-27 14:34:43 Corey Bryant neutron (Ubuntu Bionic): status Triaged In Progress
2019-03-27 16:48:50 Corey Bryant cloud-archive/pike: status In Progress Fix Committed
2019-03-27 16:48:55 Corey Bryant tags uosci uosci verification-pike-needed
2019-03-29 10:21:31 Timo Aaltonen neutron (Ubuntu Cosmic): status In Progress Fix Committed
2019-03-29 10:21:38 Timo Aaltonen bug added subscriber SRU Verification
2019-03-29 10:21:48 Timo Aaltonen tags uosci verification-pike-needed uosci verification-needed verification-needed-cosmic verification-pike-needed
2019-03-29 10:23:22 Timo Aaltonen neutron (Ubuntu Bionic): status In Progress Fix Committed
2019-03-29 10:23:33 Timo Aaltonen tags uosci verification-needed verification-needed-cosmic verification-pike-needed uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed
2019-03-29 12:54:40 Jeremy Stanley tags uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed
2019-04-01 13:45:49 Corey Bryant cloud-archive/rocky: status In Progress Fix Committed
2019-04-01 13:45:52 Corey Bryant tags pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-rocky-needed
2019-04-01 13:46:42 Corey Bryant cloud-archive/queens: status In Progress Fix Committed
2019-04-01 13:46:45 Corey Bryant tags pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-rocky-needed pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-queens-needed verification-rocky-needed
2019-04-01 14:24:07 Corey Bryant cloud-archive: status In Progress Fix Committed
2019-04-02 12:30:56 Corey Bryant neutron (Ubuntu Disco): status In Progress Fix Committed
2019-04-02 14:45:16 Corey Bryant cloud-archive: status Fix Committed Fix Released
2019-04-04 18:49:14 Jeremy Stanley ossa: status Incomplete Confirmed
2019-04-04 18:49:14 Jeremy Stanley ossa: assignee Gage Hugo (gagehugo)
2019-04-04 18:49:34 Jeremy Stanley ossa: importance Undecided Critical
2019-04-05 01:03:19 OpenStack Infra tags pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-queens-needed verification-rocky-needed in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-queens-needed verification-rocky-needed
2019-04-05 15:35:53 Gage Hugo summary [SRU] Unable to install new flows on compute nodes when having broken security group rules [SRU] Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876)
2019-04-09 15:18:24 Launchpad Janitor neutron (Ubuntu Disco): status Fix Committed Fix Released
2019-04-10 17:17:34 Jeremy Stanley ossa: status Confirmed Fix Released
2019-04-10 17:18:11 Jeremy Stanley summary [SRU] Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876) [SRU] [OSSA-2019-002] Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876)
2019-04-30 19:45:36 Corey Bryant attachment added lp-1813007-cosmic-proposed.txt https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007/+attachment/5260370/+files/lp-1813007-cosmic-proposed.txt
2019-04-30 19:46:29 Corey Bryant tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-needed verification-needed-bionic verification-needed-cosmic verification-pike-needed verification-queens-needed verification-rocky-needed in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-cosmic verification-needed verification-needed-bionic verification-pike-needed verification-queens-needed verification-rocky-needed
2019-05-01 01:50:26 Chris Halse Rogers removed subscriber Ubuntu Stable Release Updates Team
2019-05-01 02:00:46 Launchpad Janitor neutron (Ubuntu Cosmic): status Fix Committed Fix Released
2019-05-02 20:06:25 Corey Bryant attachment added lp-1813007-rocky-proposed.txt https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007/+attachment/5261000/+files/lp-1813007-rocky-proposed.txt
2019-05-02 20:07:06 Corey Bryant tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-cosmic verification-needed verification-needed-bionic verification-pike-needed verification-queens-needed verification-rocky-needed in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-cosmic verification-needed verification-needed-bionic verification-pike-needed verification-queens-needed verification-rocky-done
2019-05-08 13:48:20 Corey Bryant attachment added lp-1813007-bionic-proposed.txt https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007/+attachment/5262336/+files/lp-1813007-bionic-proposed.txt
2019-05-08 13:49:19 Corey Bryant tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-cosmic verification-needed verification-needed-bionic verification-pike-needed verification-queens-needed verification-rocky-done in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-needed verification-queens-needed verification-rocky-done
2019-05-08 14:51:40 Corey Bryant attachment added lp-1813007-queens-proposed.txt https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007/+attachment/5262365/+files/lp-1813007-queens-proposed.txt
2019-05-08 15:18:08 Corey Bryant tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-needed verification-queens-needed verification-rocky-done in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-needed verification-queens-done verification-rocky-done
2019-05-08 15:32:34 Corey Bryant attachment added lp-1813007-pike-proposed.txt https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007/+attachment/5262372/+files/lp-1813007-pike-proposed.txt
2019-05-08 15:33:02 Corey Bryant tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-needed verification-queens-done verification-rocky-done in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-done verification-queens-done verification-rocky-done
2019-05-09 09:59:28 Launchpad Janitor neutron (Ubuntu Bionic): status Fix Committed Fix Released
2019-05-13 19:19:02 Corey Bryant cloud-archive/pike: status Fix Committed Fix Released
2019-09-19 15:49:46 Tori Hegarty removed subscriber Tori Hegarty
2020-09-04 13:02:02 Slawek Kaplonski tags in-stable-stein pike-backport-potential queens-backport-potential rocky-backport-potential uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-done verification-queens-done verification-rocky-done in-stable-stein uosci verification-done-bionic verification-done-cosmic verification-needed verification-pike-done verification-queens-done verification-rocky-done