CVE-2017-5936
published 2017-04-12CVE-2017-5936: OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.91%
85.4th percentile
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| openstack | nova-lxd | <= 13.1.0 | — |
| openstack | nova-lxd | >= 0 < 13.1.1 | 13.1.1 |
| openstack | nova-lxd | >= 0 < 1b76cefb92081efa1e88cd8f330253f857028bd2 | 1b76cefb92081efa1e88cd8f330253f857028bd2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova-LXD vulnerability
vendor_ubuntu·2017-02-10
CVE-2017-5936 Nova-LXD vulnerability
Title: Nova-LXD vulnerability
Summary: Nova-LXD could allow unintended access to LXD instances over the network.
James Page discovered that Nova-LXD incorrectly set up virtual network devices
when creating LXD instances. This could result in an unintended firewall
configuration.
Instructions: In general, a standard system update will make all the necessary changes for
new instances. However, existing instances will still be affected and must be
manually updated.
OSV
OpenStack Nova-LXD bypass security restrictions
osv·2022-05-13
CVE-2017-5936 [HIGH] OpenStack Nova-LXD bypass security restrictions
OpenStack Nova-LXD bypass security restrictions
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
GHSA
OpenStack Nova-LXD bypass security restrictions
ghsa·2022-05-13
CVE-2017-5936 [HIGH] OpenStack Nova-LXD bypass security restrictions
OpenStack Nova-LXD bypass security restrictions
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
OSV
CVE-2017-5936: OpenStack Nova-LXD before 13
osv·2017-04-12
CVE-2017-5936 CVE-2017-5936: OpenStack Nova-LXD before 13
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2017/02/09/3http://www.securityfocus.com/bid/96182http://www.ubuntu.com/usn/USN-3195-1https://bugs.launchpad.net/nova-lxd/+bug/1656847https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2http://www.openwall.com/lists/oss-security/2017/02/09/3http://www.securityfocus.com/bid/96182http://www.ubuntu.com/usn/USN-3195-1https://bugs.launchpad.net/nova-lxd/+bug/1656847https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2
2017-04-12
Published