CVE-2015-8914: Critical severity neutron vulnerability
A vulnerability in Neutron anti-spoof protection. By forging DHCP discovery messages or non-IP traffic, such as ARP or ICMPv6, an instance may spoof IP or MAC source addresses on attached networks resulting in denial of services and/or traffic interception. Moreover when L2population isn't used, other tenants attached to a shared network are also vulnerable. Neutron setups using the IPTables firewall driver are affected.
Upstream bug:
https://bugs.launchpad.net/bugs/1502933
References:
http://seclists.org/oss-sec/2016/q2/519
Other sources
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8914?
CVE-2015-8914 has a medium severity rating due to the potential for denial of service and traffic interception.
How do I fix CVE-2015-8914?
To fix CVE-2015-8914, upgrade OpenStack Neutron to version 7.0.4 or higher, or to version 8.1.0 or higher.
Which versions of OpenStack Neutron are affected by CVE-2015-8914?
CVE-2015-8914 affects OpenStack Neutron versions before 7.0.4 and from 8.0.0 to 8.1.0.
What type of attack does CVE-2015-8914 allow?
CVE-2015-8914 allows remote attackers to bypass ICMPv6 spoofing protection, leading to possible denial of service or network traffic interception.
Is CVE-2015-8914 related to specific network configurations?
Yes, CVE-2015-8914 is particularly relevant for environments utilizing link-local source addresses in IPv6.