CVE-2015-3221: Input Validation
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3221?
CVE-2015-3221 has a medium severity as it allows remote authenticated users to cause a denial of service.
How do I fix CVE-2015-3221?
To fix CVE-2015-3221, upgrade OpenStack Neutron to version 2014.2.4 or higher for Juno, or version 2015.1.1 or higher for Kilo.
Who is affected by CVE-2015-3221?
CVE-2015-3221 affects OpenStack Neutron deployments that use the IPTables firewall driver prior to the specified versions.
What can an attacker do with CVE-2015-3221?
An attacker can trigger an L2 agent crash by adding an address pair that is rejected by the ipset tool.
What are the affected versions for CVE-2015-3221?
The affected versions for CVE-2015-3221 are OpenStack Neutron before 2014.2.4 and 2015.1.x before 2015.1.1.