REDHAT-BUG-1345892: Low severity neutron vulnerability
A vulnerability in Neutron anti-spoof protection. By forging DHCP discovery messages or non-IP traffic, such as ARP or ICMPv6, an instance may spoof IP or MAC source addresses on attached networks resulting in denial of services and/or traffic interception. Moreover when L2population isn't used, other tenants attached to a shared network are also vulnerable. Neutron setups using the IPTables firewall driver are affected.
Upstream bug:
https://bugs.launchpad.net/bugs/1502933
References:
http://seclists.org/oss-sec/2016/q2/519
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1345892?
The severity of REDHAT-BUG-1345892 is considered high due to its potential for IP and MAC spoofing and resultant denial of service.
How do I fix REDHAT-BUG-1345892?
To fix REDHAT-BUG-1345892, ensure that L2population is used and apply the relevant patches provided by OpenStack for Neutron.
What systems are affected by REDHAT-BUG-1345892?
REDHAT-BUG-1345892 affects systems utilizing OpenStack Neutron without L2population enabled.
What are the risks of not addressing REDHAT-BUG-1345892?
Not addressing REDHAT-BUG-1345892 can lead to unauthorized traffic interception and service disruptions within affected networks.
Is there a workaround for REDHAT-BUG-1345892?
A possible workaround for REDHAT-BUG-1345892 is to enable L2population in your OpenStack Neutron configuration.