CVE-2014-2828
published 2014-04-15CVE-2014-2828: The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU…
PriorityP341high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.16%
86.5th percentile
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2014.1-1 (bookworm) | keystone 2014.1-1 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-keystone: denial of service via V3 API authentication chaining
vendor_redhat·2014-03-31·CVSS 7.8
CVE-2014-2828 [HIGH] CWE-20 openstack-keystone: denial of service via V3 API authentication chaining
openstack-keystone: denial of service via V3 API authentication chaining
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
A flaw was found in the keystone V3 API. An attacker could send a single request with the same authentication method multiple times, possibly leading to a denial of service due to generating excessive load with minimal requests. Only keystone setups with the V3 API enabled were affected by this issue.
Package: openstack-keystone (Red Hat OpenStack Platform 3) - Will not fix
Debian
CVE-2014-2828: keystone - The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse ...
vendor_debian·2014·CVSS 7.8
CVE-2014-2828 [HIGH] CVE-2014-2828: keystone - The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse ...
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
Scope: local
bookworm: resolved (fixed in 2014.1-1)
bullseye: resolved (fixed in 2014.1-1)
forky: resolved (fixed in 2014.1-1)
sid: resolved (fixed in 2014.1-1)
trixie: resolved (fixed in 2014.1-1)
OSV
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
osv·2022-05-17
CVE-2014-2828 [HIGH] OpenStack Identity (Keystone) DoS through V3 API authentication chaining
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
GHSA
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
ghsa·2022-05-17
CVE-2014-2828 [HIGH] CWE-287 OpenStack Identity (Keystone) DoS through V3 API authentication chaining
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
OSV
CVE-2014-2828: The V3 API in OpenStack Identity (Keystone) 2013
osv·2014-04-15·CVSS 7.8
CVE-2014-2828 [HIGH] CVE-2014-2828: The V3 API in OpenStack Identity (Keystone) 2013
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53629 kernel: fs: dlm: fix use after free in midcomms commit
bugzilla·2025-10-07·CVSS 7.8
CVE-2023-53629 [HIGH] CVE-2023-53629 kernel: fs: dlm: fix use after free in midcomms commit
CVE-2023-53629 kernel: fs: dlm: fix use after free in midcomms commit
In the Linux kernel, the following vulnerability has been resolved:
fs: dlm: fix use after free in midcomms commit
While working on processing dlm message in softirq context I experienced
the following KASAN use-after-free warning:
[ 151.760477] ==================================================================
[ 151.761803] BUG: KASAN: use-after-free in dlm_midcomms_commit_mhandle+0x19d/0x4b0
[ 151.763414] Read of size 4 at addr ffff88811a980c60 by task lock_torture/1347
[ 151.765284] CPU: 7 PID: 1347 Comm: lock_torture Not tainted 6.1.0-rc4+ #2828
[ 151.766778] Hardware name: Red Hat KVM/RHEL-AV, BIOS 1.16.0-3.module+el8.7.0+16134+e5908aa2 04/01/2014
[ 151.768726] Call Trace:
[ 151.769277]
[ 151.769748] dump_stack
Bugzilla
CVE-2014-2828 openstack-keystone: denial of service via V3 API authentication chaining
bugzilla·2014-04-10·CVSS 7.8
CVE-2014-2828 [HIGH] CVE-2014-2828 openstack-keystone: denial of service via V3 API authentication chaining
CVE-2014-2828 openstack-keystone: denial of service via V3 API authentication chaining
The following was reported to the oss-security list:
Title: Keystone DoS through V3 API authentication chaining
Reporter: Abu Shohel Ahmed (Ericsson)
Products: Keystone
Versions: from 2013.1 to 2013.2.3
Description:
Abu Shohel Ahmed from Ericsson reported a vulnerability in Keystone V3
API authentication. By sending a single request with the same
authentication method multiple times, a remote attacker may generate
unwanted load on the Keystone host, potentially resulting in a Denial of
Service against a Keystone service. Only Keystone setups enabling V3 API
are affected.
References:
https://launchpad.net/bugs/1300274
http://seclists.org/oss-sec/2014/q2/65
https://review.openstack.org/#/c/86024/
https
http://rhn.redhat.com/errata/RHSA-2014-1688.htmlhttp://www.openwall.com/lists/oss-security/2014/04/10/20https://bugs.launchpad.net/keystone/+bug/1300274http://rhn.redhat.com/errata/RHSA-2014-1688.htmlhttp://www.openwall.com/lists/oss-security/2014/04/10/20https://bugs.launchpad.net/keystone/+bug/1300274
2014-04-15
Published