CVE-2019-10876

Severity
6.5MEDIUM
EPSS
0.6%
top 29.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 5
Latest updateMay 13

Description

An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDopenstack/neutron11.0.011.0.7+2
PyPIneutron11.0.011.0.7+2
Debianneutron< 2:13.0.2-15+3
NVDredhat/openstack13, 14+1

🔴Vulnerability Details

4
OSV
OpenStack Neutron overlapping security group rules prevents compute node network configuration2022-05-13
GHSA
OpenStack Neutron overlapping security group rules prevents compute node network configuration2022-05-13
OSV
CVE-2019-10876: An issue was discovered in OpenStack Neutron 112019-04-05
CVEList
CVE-2019-10876: An issue was discovered in OpenStack Neutron 112019-04-05

📋Vendor Advisories

2
Red Hat
openstack-neutron: DOS via broken port range merging in security group2019-02-28
Debian
CVE-2019-10876: neutron - An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12....2019

💬Community

4
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-rdo]2019-04-03
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group2019-04-03
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-13-default]2019-04-03
Bugzilla
CVE-2018-10876 kernel: use-after-free in jbd2_journal_commit_transaction funtion2018-06-29
CVE-2019-10876 (MEDIUM CVSS 6.5) | An issue was discovered in OpenStac | cvebase.io