CVE-2021-38598: Critical severity Openstack Neutron vulnerability
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 17.1.3 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 16.4.1
Event History
Frequently Asked Questions
What is CVE-2021-38598?
CVE-2021-38598 is a vulnerability in OpenStack Neutron that allows hardware address impersonation.
Which versions of OpenStack Neutron are affected by CVE-2021-38598?
OpenStack Neutron versions before 16.4.1, 17.x before 17.1.3, and 18.0.0 are affected by CVE-2021-38598.
What is the severity of CVE-2021-38598?
CVE-2021-38598 has a severity rating of 9.1 (critical).
How does CVE-2021-38598 allow hardware address impersonation?
CVE-2021-38598 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform.
Is there a fix for CVE-2021-38598?
Yes, upgrading to OpenStack Neutron version 16.4.1, 17.1.3, or 18.0.0 will fix CVE-2021-38598.