Описание
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
An input-validation flaw was found in openstack-neutron, where an authenticated attacker could change the dnsmasq configuration. By crafting extra_dhcp_opts values, the attacker could crash the dnsmasq, change parameters for tenants sharing the same interface, or otherwise alter that daemon’s behavior. This flaw might also be used to trigger a configuration parsing buffer overflow in versions of dnsmasq prior to 2.81. The highest threat from this vulnerability is to system availability, but also threatens data confidentiality and integrity.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Integration Camel K 1 | openstack-neutron | Not affected | ||
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-neutron | Fixed | RHSA-2021:3502 | 13.09.2021 |
| Red Hat OpenStack Platform 13.0 - ELS | openstack-neutron | Fixed | RHSA-2021:3503 | 13.09.2021 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | openstack-neutron | Fixed | RHSA-2021:3503 | 13.09.2021 |
| Red Hat OpenStack Platform 16.1 | openstack-neutron | Fixed | RHSA-2021:3481 | 09.09.2021 |
| Red Hat OpenStack Platform 16.2 | openstack-neutron | Fixed | RHSA-2021:3488 | 15.09.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x befor ...
OpenStack Neutron vulnerable to authenticated attackers reconfiguring dnsmasq via crafted extra_dhcp_opts value
EPSS
7.6 High
CVSS3