CVE-2014-8153: Input Validation
Published Jan 15, 2015
·Updated
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.
Affected Software
3 affected components
Litech Router Advertisement Daemon=2.0
Openstack Neutron=2014.2
Openstack Neutron=2014.2.1
Event History
Jan 15, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8153?
CVE-2014-8153 is classified as a denial of service vulnerability.
2
How do I fix CVE-2014-8153?
To fix CVE-2014-8153, upgrade OpenStack Neutron to version 2014.2.2 or later.
3
What kind of attack does CVE-2014-8153 allow?
CVE-2014-8153 allows remote authenticated users to block router update processing.
4
Which versions of OpenStack Neutron are affected by CVE-2014-8153?
OpenStack Neutron versions 2014.2.x before 2014.2.2 are affected by CVE-2014-8153.
5
Is there a known workaround for CVE-2014-8153?
There are no documented workarounds for CVE-2014-8153; upgrading is recommended.