CVE-2017-15114: Critical severity red hat openstack platform vulnerability
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-15114?
CVE-2017-15114 is a vulnerability in libvirtd when configured to use the TLS transport without additional authentication.
How does CVE-2017-15114 affect Redhat Openstack Platform 12.0?
Redhat Openstack Platform 12.0 is affected by CVE-2017-15114 if libvirtd is configured to use the TLS transport.
What is the severity of CVE-2017-15114?
The severity of CVE-2017-15114 is critical (8.1).
How can I fix CVE-2017-15114?
To fix CVE-2017-15114, apply the patch provided in the reference link.
Where can I find more information about CVE-2017-15114?
You can find more information about CVE-2017-15114 in the reference links provided.