Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:2220-1

Опубликовано: 07 дек. 2015
Источник: suse-cvrf

Описание

Security update for openstack-nova and openstack-neutron

This update for openstack-nova and openstack-neutron provides various fixes and improvements.

openstack-nova:

  • Fix instance filtering. (bsc#927625)
  • Remove error messages from multipath command output before parsing. (bsc#949529)
  • Fix live-migration usage of the wrong connector information.
  • Added requirement for memcached to python-nova. (bsc#942457)
  • Don't expect meta attributes in object_compat that aren't in the db obj. (bsc#949070, CVE-2015-7713)
  • Kill rsync/scp processes before deleting instance. (bsc#935017, CVE-2015-3241)
  • Sync process utils from oslo for execute callbacks. (bsc#935017, CVE-2015-3241)
  • Fix rebuild of an instance with a volume attached.
  • Fixes _cleanup_rbd code to capture ImageBusy exception.
  • Don't try to confine a non-NUMA instance.
  • Include blank volumes in the block device mapping (bsc#945923)
  • Delete orphaned instance files from compute nodes (bsc#944178, CVE-2015-3280)

openstack-neutron:

  • Fix usage_audit to work with ML2.
  • Fix UDP offloading issue with virtio VMs. (bsc#948704)
  • Fix ipset can't be destroyed when last rule is deleted.
  • Add ARP spoofing protection for LinuxBridge agent.
  • Don't use ARP responder for IPv6 addresses in ovs.
  • Stop device_owner from being set to 'network:*'. (bsc#943648, CVE-2015-5240)
  • NSX-mh: use router_distributed flag.
  • NSX-mh: Failover controller connections on socket failures.
  • NSX-mh: Prevent failures on router delete.

Список пакетов

SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5
openstack-neutron-2014.2.4~a0~dev103-10.3
openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-lbaas-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-linuxbridge-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-metadata-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-metering-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-openvswitch-agent-2014.2.4~a0~dev103-10.3
openstack-neutron-vpn-agent-2014.2.4~a0~dev103-10.3
openstack-nova-2014.2.4~a0~dev80-14.1
openstack-nova-compute-2014.2.4~a0~dev80-14.1
python-neutron-2014.2.4~a0~dev103-10.3
python-nova-2014.2.4~a0~dev80-14.1
python-python-memcached-1.54-2.1

Описание

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.


Затронутые продукты
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3

Ссылки

Описание

OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.


Затронутые продукты
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3

Ссылки

Описание

OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.


Затронутые продукты
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3

Ссылки

Описание

Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.


Затронутые продукты
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3

Ссылки

Описание

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.


Затронутые продукты
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-dhcp-agent-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-ha-tool-2014.2.4~a0~dev103-10.3
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5:openstack-neutron-l3-agent-2014.2.4~a0~dev103-10.3

Ссылки