CVE-2018-14635
published 2018-09-10CVE-2018-14635: When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.53%
83.1th percentile
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2:13.0.0-1 (bookworm) | neutron 2:13.0.0-1 (bookworm) |
| openstack | neutron | — | — |
| openstack | neutron | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | neutron | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | neutron | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | neutron | >= 0 < 2:13.0.0-1 | 2:13.0.0-1 |
| openstack | neutron | >= 0 < 11.0.6 | 11.0.6 |
| openstack | neutron | 11.0.0 – 11.0.5 | — |
| openstack | neutron | >= 12.0.0 < 12.0.4 | 12.0.4 |
| openstack | neutron | 12.0.0 – 12.0.3 | — |
| openstack | neutron | >= 13.0.0.0b1 < 13.0.0.0b2 | 13.0.0.0b2 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| the_openstack_project | openstack-neutron | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-neutron: A router interface out of subnet IP range results in a denial of service
vendor_redhat·2018-03-21·CVSS 6.5
CVE-2018-14635 [MEDIUM] CWE-20 openstack-neutron: A router interface out of subnet IP range results in a denial of service
openstack-neutron: A router interface out of subnet IP range results in a denial of service
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned fr
Debian
CVE-2018-14635: neutron - When using the Linux bridge ml2 driver, non-privileged tenants are able to creat...
vendor_debian·2018·CVSS 6.5
CVE-2018-14635 [MEDIUM] CVE-2018-14635: neutron - When using the Linux bridge ml2 driver, non-privileged tenants are able to creat...
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:13.0.0-1)
bullseye: resolved (fixed in 2:13.0.0-1)
forky: resolved (fixed in 2:13.0.0-1)
sid: resolved (fixed in 2:13.0.0-1)
trixie: resolved (fixed in 2:13.0.0-1)
OSV
OpensStack Neutron Denial of Service Vulnerability
osv·2022-05-13
CVE-2018-14635 [HIGH] OpensStack Neutron Denial of Service Vulnerability
OpensStack Neutron Denial of Service Vulnerability
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
GHSA
OpensStack Neutron Denial of Service Vulnerability
ghsa·2022-05-13
CVE-2018-14635 [HIGH] CWE-20 OpensStack Neutron Denial of Service Vulnerability
OpensStack Neutron Denial of Service Vulnerability
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
OSV
CVE-2018-14635: When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP addr
osv·2018-09-10·CVSS 6.5
CVE-2018-14635 [MEDIUM] CVE-2018-14635: When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP addr
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service [openstack-rdo]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14635 [MEDIUM] CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service [openstack-rdo]
CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Dis
Bugzilla
CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14635 [MEDIUM] CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service
CVE-2018-14635 openstack-neutron: A router interface out of subnet IP range results in a denial of service
It was found that a non privileged tenant can add a router interface to a shared / external network's subnet with an IP address outside the subnet's allocation pool. This can result in a Denial of Service.
Upstream issue:
https://bugs.launchpad.net/neutron/+bug/1757482
Upstream patch:
https://git.openstack.org/cgit/openstack/neutron/commit/?id=54aa6e81cb17b33ce4d5d469cc11dec2869c762d
Discussion:
Created openstack-neutron tracking bugs for this issue:
Affects: openstack-rdo [bug 1607824]
---
Hi Andrej,
The fix has been merged to the upstream master branch and backports were proposed in Ocata to Queens (equiv. to OSP 11 to 13). We'll need to do a downstream only backport to O
https://access.redhat.com/errata/RHSA-2018:2710https://access.redhat.com/errata/RHSA-2018:2715https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:3792https://bugs.launchpad.net/neutron/+bug/1757482https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14635https://git.openstack.org/cgit/openstack/neutron/commit/?id=54aa6e81cb17b33ce4d5d469cc11dec2869c762dhttps://access.redhat.com/errata/RHSA-2018:2710https://access.redhat.com/errata/RHSA-2018:2715https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:3792https://bugs.launchpad.net/neutron/+bug/1757482https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14635https://git.openstack.org/cgit/openstack/neutron/commit/?id=54aa6e81cb17b33ce4d5d469cc11dec2869c762d
2018-09-10
Published