REDHAT-BUG-1345891: Low severity neutron vulnerability
A vulnerability in Neutron anti-spoof protection. By forging DHCP discovery messages or non-IP traffic, such as ARP or ICMPv6, an instance may spoof IP or MAC source addresses on attached networks resulting in denial of services and/or traffic interception. Moreover when L2population isn't used, other tenants attached to a shared network are also vulnerable. Neutron setups using the IPTables firewall driver are affected.
Upstream bug:
https://bugs.launchpad.net/bugs/1558658
References:
http://seclists.org/oss-sec/2016/q2/519
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1345891?
The vulnerability REDHAT-BUG-1345891 is rated as high severity due to its potential to cause denial of service and traffic interception.
How do I fix REDHAT-BUG-1345891?
To fix REDHAT-BUG-1345891, ensure that you're using the latest version of OpenStack Neutron where the vulnerability has been patched.
What systems are affected by REDHAT-BUG-1345891?
The REDHAT-BUG-1345891 vulnerability affects installations of OpenStack Neutron that do not implement L2population.
What can happen if REDHAT-BUG-1345891 is exploited?
Exploitation of REDHAT-BUG-1345891 can allow an attacker to spoof IP or MAC addresses, leading to unauthorized access and data interception.
Is there a workaround for REDHAT-BUG-1345891?
Currently, the primary recommendation for REDHAT-BUG-1345891 is to update to a patched version of OpenStack Neutron, as no specific workaround is provided.