First published: Wed Aug 26 2015(Updated: )
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | >=2014.2<2014.2.4 | |
OpenStack Neutron | >=2015.1.0<2015.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3221 has a medium severity as it allows remote authenticated users to cause a denial of service.
To fix CVE-2015-3221, upgrade OpenStack Neutron to version 2014.2.4 or higher for Juno, or version 2015.1.1 or higher for Kilo.
CVE-2015-3221 affects OpenStack Neutron deployments that use the IPTables firewall driver prior to the specified versions.
An attacker can trigger an L2 agent crash by adding an address pair that is rejected by the ipset tool.
The affected versions for CVE-2015-3221 are OpenStack Neutron before 2014.2.4 and 2015.1.x before 2015.1.1.