Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v725-c588-h936

Опубликовано: 04 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

OpenStack Nova Changing vnic_type breaks compute service restart

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 23.2.2

23.2.2

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 24.0.0, < 24.1.2

24.1.2

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 25.0.0, < 25.0.2

25.0.2

EPSS

Процентиль: 18%
0.00058
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3: 3.3
redhat
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3: 3.3
nvd
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3: 3.3
debian
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 2 ...

EPSS

Процентиль: 18%
0.00058
Низкий

3.3 Low

CVSS3