CVE-2019-10876: Medium severity Openstack Neutron vulnerability
A flaw was found in openstack-neutron. When merging port ranges, the code never assumed the conjunction ID might not be present in the set due to already being removed. This can lead to server crash and denial of service.
Upstream patch:
https://review.openstack.org/#/c/640252/ https://review.openstack.org/#/c/648102/2 https://review.openstack.org/#/c/648004/2 https://review.openstack.org/#/c/648003/2 https://review.openstack.org/#/c/648002/2
References:
https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007 https://bugs.launchpad.net/ossa/+bug/1813007 https://review.openstack.org/#/q/topic:bug/1813007
Other sources
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 13.0.3 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 12.0.6 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 11.0.7 - Upgrade
Upgrade
redhat/neutronto a version that resolves this vulnerability.Fixed in 11.0.7 - Upgrade
Upgrade
redhat/neutronto a version that resolves this vulnerability.Fixed in 12.0.6 - Upgrade
Upgrade
redhat/neutronto a version that resolves this vulnerability.Fixed in 13.0.3 - Upgrade
Upgrade
openstack-neutronto a version that resolves this vulnerability.Fixed in 11.0.7 - Upgrade
Upgrade
openstack-neutronto a version that resolves this vulnerability.Fixed in 12.0.6 - Upgrade
Upgrade
openstack-neutronto a version that resolves this vulnerability.Fixed in 13.0.3 - Compensating control
For Neutron deployments using neutron-openvswitch-agent, avoid creating two security groups whose port ranges have separate/overlapping ranges on compute nodes until patched; this prevents triggering the OVS firewall KeyError that can crash/nearly deny service.
Event History
Frequently Asked Questions
What is CVE-2019-10876?
CVE-2019-10876 is a vulnerability in OpenStack Neutron versions before 11.0.7, 12.0.6, and 13.0.3 that allows an authenticated user to prevent Neutron from configuring networks on compute nodes.
How can an attacker exploit CVE-2019-10876?
By creating two security groups with separate/overlapping port ranges, an authenticated user can exploit CVE-2019-10876.
What is the severity of CVE-2019-10876?
CVE-2019-10876 has a severity rating of 6.5 out of 10 (medium).
Which versions of OpenStack Neutron are affected by CVE-2019-10876?
OpenStack Neutron versions before 11.0.7, 12.0.6, and 13.0.3 are affected by CVE-2019-10876.
How can I fix CVE-2019-10876?
To fix CVE-2019-10876, upgrade your OpenStack Neutron installation to version 11.0.7, 12.0.6, or 13.0.3.