CVE-2017-7543
published 2018-07-26CVE-2017-7543: A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.85%
76.7th percentile
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | — | — |
| openstack | neutron | >= 0 < 7.2.0-12.1 | 7.2.0-12.1 |
| openstack | neutron | >= 10.0.0 < 10.0.2-1.1 | 10.0.2-1.1 |
| openstack | neutron | >= 10.0.0 < 10.0.2-1.1 | 10.0.2-1.1 |
| openstack | neutron | >= 7.0.0 < 7.2.0-12.1 | 7.2.0-12.1 |
| openstack | neutron | >= 8.0.0 < 8.3.0-11.1 | 8.3.0-11.1 |
| openstack | neutron | >= 8.0.0 < 8.3.0-11.1 | 8.3.0-11.1 |
| openstack | neutron | >= 9.0.0 < 9.3.1-2.1 | 9.3.1-2.1 |
| openstack | neutron | >= 9.0.0 < 9.3.1-2.1 | 9.3.1-2.1 |
| red_hat | openstack-neutron | — | — |
| red_hat | openstack-neutron | — | — |
| red_hat | openstack-neutron | — | — |
| red_hat | openstack-neutron | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Neutron Race Condition vulnerability
osv·2022-05-13
CVE-2017-7543 [MEDIUM] OpenStack Neutron Race Condition vulnerability
OpenStack Neutron Race Condition vulnerability
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
GHSA
OpenStack Neutron Race Condition vulnerability
ghsa·2022-05-13
CVE-2017-7543 [MEDIUM] CWE-362 OpenStack Neutron Race Condition vulnerability
OpenStack Neutron Race Condition vulnerability
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
Red Hat
openstack-neutron: iptables not active after update
vendor_redhat·2017-08-08·CVSS 5.3
CVE-2017-7543 [MEDIUM] CWE-362 openstack-neutron: iptables not active after update
openstack-neutron: iptables not active after update
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
A race-condition flaw was discovered in openstack-neutron where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race
Debian
CVE-2017-7543: neutron - A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x...
vendor_debian·2017·CVSS 5.3
CVE-2017-7543 [MEDIUM] CVE-2017-7543: neutron - A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x...
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7543 openstack-neutron: iptables not active after update
bugzilla·2017-07-21·CVSS 5.3
CVE-2017-7543 [MEDIUM] CVE-2017-7543 openstack-neutron: iptables not active after update
CVE-2017-7543 openstack-neutron: iptables not active after update
Paul Needle of Red Hat reports:
iptables/firewalld is not active on overcloud compute and controller nodes, following an 'openstack overcloud update ...' procedure run in a production environment yesterday. This has major impact given that there are end-customer workloads running in this environment.
Discussion:
Acknowledgements:
Name: Paul Needle (Red Hat)
---
All bugs except OSP12 are in MODIFIED now. OSP12 will get the fix through regular RDO sync process (we can leave it without a OSP fix for the time being because it was not released yet).
---
Mitigation:
To determine whether your system is impacted, run:
$ sudo sysctl net.bridge.bridge-nf-call-ip6tables
$ sudo sysctl net.bridge.bridge-nf-call-iptables
Both sh
Bugzilla
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
bugzilla·2016-09-27·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
Shells running as root inherited PS4 from the environment, allowing PS4 expansion performing command substitution. Local attacker could gain arbitrary code execution via bogus setuid binaries using system()/popen() by specially crafting SHELLOPTS+PS4 environment variables.
Public announcement:
http://seclists.org/oss-sec/2016/q3/617
Discussion:
Created bash tracking bugs for this issue:
Affects: fedora-all [bug 1379634]
---
Upstream patch (for bash-4.3):
http://lists.gnu.org/archive/html/bug-bash/2016-10/msg00009.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0725 https://rhn.redhat.com/errata/RHSA-2017-0725.html
---
This issue
http://www.securityfocus.com/bid/100237https://access.redhat.com/errata/RHSA-2017:2447https://access.redhat.com/errata/RHSA-2017:2448https://access.redhat.com/errata/RHSA-2017:2449https://access.redhat.com/errata/RHSA-2017:2450https://access.redhat.com/errata/RHSA-2017:2451https://access.redhat.com/errata/RHSA-2017:2452https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7543http://www.securityfocus.com/bid/100237https://access.redhat.com/errata/RHSA-2017:2447https://access.redhat.com/errata/RHSA-2017:2448https://access.redhat.com/errata/RHSA-2017:2449https://access.redhat.com/errata/RHSA-2017:2450https://access.redhat.com/errata/RHSA-2017:2451https://access.redhat.com/errata/RHSA-2017:2452https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7543
2018-07-26
Published