Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-37394

Опубликовано: 03 авг. 2022
Источник: redhat
CVSS3: 3.3

Описание

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-novaOut of support scope
Red Hat OpenStack Platform 16.1openstack-novaFix deferred
Red Hat OpenStack Platform 17.0openstack-novaOut of support scope
Red Hat OpenStack Platform 16.2openstack-novaFixedRHSA-2023:194826.04.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2117333openstack-nova: Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3: 3.3
nvd
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3: 3.3
debian
больше 3 лет назад

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 2 ...

CVSS3: 3.3
github
больше 3 лет назад

OpenStack Nova Changing vnic_type breaks compute service restart

3.3 Low

CVSS3