CVE-2021-40085: Medium severity Openstack Neutron vulnerability
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extradhcpopts value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/neutronto a version that resolves this vulnerability.Fixed in 2:13.0.7+git.2021.09.27.bace3d1890-0+deb10u1Fixed in 2:17.2.1-0+deb11u1Fixed in 2:21.0.0-7Fixed in 2:23.0.0-2 - Upgrade
Upgrade
debian/neutronto a version that resolves this vulnerability.Fixed in 2:18.1.0-3Fixed in 2:13.0.7+git.2021.09.27.bace3d1890-0+deb10u1Fixed in 2:19.0.0~rc1-1Fixed in 2:17.2.1-0+deb11u1 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 18.1.1 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 17.2.1 - Upgrade
Upgrade
pip/neutronto a version that resolves this vulnerability.Fixed in 16.4.1 - Upgrade
Upgrade
OpenStack Neutronto a version that resolves this vulnerability.Fixed in 16.4.1 - Upgrade
Upgrade
OpenStack Neutronto a version that resolves this vulnerability.Fixed in 17.2.1 - Upgrade
Upgrade
OpenStack Neutronto a version that resolves this vulnerability.Fixed in 18.1.1
Event History
Frequently Asked Questions
What is CVE-2021-40085?
CVE-2021-40085 is a vulnerability discovered in OpenStack Neutron that allows authenticated attackers to reconfigure dnsmasq via a crafted extra_dhcp_opts value.
How can the CVE-2021-40085 vulnerability be exploited?
The CVE-2021-40085 vulnerability can be exploited by authenticated attackers who can manipulate the extra_dhcp_opts value to reconfigure dnsmasq.
What is the severity of CVE-2021-40085?
The severity of CVE-2021-40085 is medium, with a severity value of 6.5.
Which versions of OpenStack Neutron are affected by CVE-2021-40085?
OpenStack Neutron versions before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1 are affected by CVE-2021-40085.
How can I fix the CVE-2021-40085 vulnerability?
To fix the CVE-2021-40085 vulnerability, update your OpenStack Neutron to version 16.4.1, 17.2.1, or 18.1.1.