CVE-2017-7543: Race Condition

Published Jul 21, 2017
·
Updated

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

Other sources

Paul Needle of Red Hat reports:

iptables/firewalld is not active on overcloud compute and controller nodes, following an 'openstack overcloud update ...' procedure run in a production environment yesterday. This has major impact given that there are end-customer workloads running in this environment.

Red Hat

Affected Software

11 affected components
Openstack Neutron>=7.0.0<7.2.0-12.1
Openstack Neutron>=8.0.0<8.3.0-11.1
Openstack Neutron>=9.0.0<9.3.1-2.1
Openstack Neutron>=10.0.0<10.0.2-1.1
redhat Openstack=6.0
redhat Enterprise Linux=7.0
redhat Openstack=7.0
redhat Openstack=8
redhat Openstack=9
redhat Openstack=10
redhat Openstack=11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openstack-neutron to a version that resolves this vulnerability.

    Fixed in 7.2.0-12.1
  2. Upgrade

    Upgrade openstack-neutron to a version that resolves this vulnerability.

    Fixed in 8.3.0-11.1
  3. Upgrade

    Upgrade openstack-neutron to a version that resolves this vulnerability.

    Fixed in 9.3.1-2.1
  4. Upgrade

    Upgrade openstack-neutron to a version that resolves this vulnerability.

    Fixed in 10.0.2-1.1
  5. Configuration

    Set net.bridge.bridge-nf-call-iptables back to a non-zero value after the overcloud minor update if it was reset to 0; the reported issue is that it was reset to 0 for neutron security groups to be disabled.

    Linux kernel netfilter sysctl net.bridge.bridge-nf-call-iptables = 0
  6. Configuration

    Set net.bridge.bridge-nf-call-ip6tables back to a non-zero value after the overcloud minor update if it was reset to 0; the reported issue is that it was reset to 0 for neutron security groups to be disabled.

    Linux kernel netfilter sysctl net.bridge.bridge-nf-call-ip6tables = 0
  7. Compensating control

    Because iptables/firewalld is not active on overcloud compute and controller nodes after the 'openstack overcloud update' procedure, enable/activate iptables or firewalld on those nodes to restore network filtering while remediation is applied.

Event History

Jul 21, 2017
Data Sourced
via Red Hat·04:44 PM
DescriptionSeverityAffected Software
Jul 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-7543?

CVE-2017-7543 is classified as a moderate severity vulnerability due to the risk of neutron security groups being disabled after an overcloud update.

2

How do I fix CVE-2017-7543?

To fix CVE-2017-7543, you should upgrade OpenStack Neutron to versions 7.2.0-12.1, 8.3.0-11.1, 9.3.1-2.1, or 10.0.2-1.1 or later.

3

Who is affected by CVE-2017-7543?

CVE-2017-7543 affects users of OpenStack Neutron versions prior to 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1.

4

What specific issue does CVE-2017-7543 cause?

CVE-2017-7543 causes a race-condition flaw that can disable neutron security groups after a minor overcloud update.

5

Is there a workaround for CVE-2017-7543?

There are no specific workarounds for CVE-2017-7543; upgrading to a fixed version is the recommended course of action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203