CVE-2019-10876
published 2019-04-05CVE-2019-10876: An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.76%
75.4th percentile
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2:13.0.2-15 (bookworm) | neutron 2:13.0.2-15 (bookworm) |
| openstack | neutron | >= 0 < 2:13.0.2-15 | 2:13.0.2-15 |
| openstack | neutron | >= 0 < 2:13.0.2-15 | 2:13.0.2-15 |
| openstack | neutron | >= 0 < 2:13.0.2-15 | 2:13.0.2-15 |
| openstack | neutron | >= 0 < 2:13.0.2-15 | 2:13.0.2-15 |
| openstack | neutron | >= 11.0.0 < 11.0.7 | 11.0.7 |
| openstack | neutron | >= 11.0.0 < 11.0.7 | 11.0.7 |
| openstack | neutron | >= 12.0.0 < 12.0.6 | 12.0.6 |
| openstack | neutron | >= 12.0.0 < 12.0.6 | 12.0.6 |
| openstack | neutron | >= 13.0.0 < 13.0.3 | 13.0.3 |
| openstack | neutron | >= 13.0.0 < 13.0.3 | 13.0.3 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Neutron overlapping security group rules prevents compute node network configuration
osv·2022-05-13
CVE-2019-10876 [HIGH] OpenStack Neutron overlapping security group rules prevents compute node network configuration
OpenStack Neutron overlapping security group rules prevents compute node network configuration
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
GHSA
OpenStack Neutron overlapping security group rules prevents compute node network configuration
ghsa·2022-05-13
CVE-2019-10876 [HIGH] OpenStack Neutron overlapping security group rules prevents compute node network configuration
OpenStack Neutron overlapping security group rules prevents compute node network configuration
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
OSV
CVE-2019-10876: An issue was discovered in OpenStack Neutron 11
osv·2019-04-05·CVSS 6.5
CVE-2019-10876 [MEDIUM] CVE-2019-10876: An issue was discovered in OpenStack Neutron 11
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Red Hat
openstack-neutron: DOS via broken port range merging in security group
vendor_redhat·2019-02-28·CVSS 6.5
CVE-2019-10876 [MEDIUM] CWE-20 openstack-neutron: DOS via broken port range merging in security group
openstack-neutron: DOS via broken port range merging in security group
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Statement: The pre-requisites for this vulnerability are not in Red Hat OpenStack prior to version 11, hence these versions are not affected.
Package: openstack-neutron (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: openstack-neutron (Red Hat OpenStack Platfo
Debian
CVE-2019-10876: neutron - An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12....
vendor_debian·2019·CVSS 6.5
CVE-2019-10876 [MEDIUM] CVE-2019-10876: neutron - An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12....
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Scope: local
bookworm: resolved (fixed in 2:13.0.2-15)
bullseye: resolved (fixed in 2:13.0.2-15)
forky: resolved (fixed in 2:13.0.2-15)
sid: resolved (fixed in 2:13.0.2-15)
trixie: resolved (fixed in 2:13.0.2-15)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-rdo]
bugzilla·2019-04-03·CVSS 6.5
CVE-2019-10876 [MEDIUM] CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-rdo]
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO includes
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group
bugzilla·2019-04-03·CVSS 6.5
CVE-2019-10876 [MEDIUM] CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group
A flaw was found in openstack-neutron. When merging port ranges, the code never assumed the conjunction ID might not be present in the set due to
already being removed. This can lead to server crash and denial of service.
Upstream patch:
https://review.openstack.org/#/c/640252/
https://review.openstack.org/#/c/648102/2
https://review.openstack.org/#/c/648004/2
https://review.openstack.org/#/c/648003/2
https://review.openstack.org/#/c/648002/2
References:
https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007
https://bugs.launchpad.net/ossa/+bug/1813007
https://review.openstack.org/#/q/topic:bug/1813007
Discussion:
Created openstack-neutron tracking bugs for this issue:
Affects: openstack-r
Bugzilla
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-13-default]
bugzilla·2019-04-03·CVSS 6.5
CVE-2019-10876 [MEDIUM] CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-13-default]
CVE-2019-10876 openstack-neutron: DOS via broken port range merging in security group [openstack-13-default]
+++ This bug was initially created as a clone of Bug #1695450 +++
It appears that we have found that neutron-openvswitch-agent appears to have a bug where two security group rules that have two different port ranges that overlap tied to the same parent security group will cause neutron to not be able to configure networks on the compute nodes where those security groups are present.
Those are the broken security rules: https://pastebin.canonical.com/p/wSy8RSXt85/
Here is the log when we discovered the issue: https://pastebin.canonical.com/p/wvFKjNWydr/
It affects only openvswitch firewall driver.
Backports proposed U/S: https://review.openstack.org/#/q/I17ab643abbd2ec21eda4ae1df
Bugzilla
CVE-2018-10876 kernel: use-after-free in jbd2_journal_commit_transaction funtion
bugzilla·2018-06-29·CVSS 5.0
CVE-2018-10876 [MEDIUM] CVE-2018-10876 kernel: use-after-free in jbd2_journal_commit_transaction funtion
CVE-2018-10876 kernel: use-after-free in jbd2_journal_commit_transaction funtion
A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=199403
http://patchwork.ozlabs.org/patch/929239/
An upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8844618d8aa7a9973e7b527d038a2a589665002c
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1596774]
---
This is fixed for Fedora with the 4.17.6 stable kernel update
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0525 https://access.redhat.
http://www.openwall.com/lists/oss-security/2019/04/09/2https://access.redhat.com/errata/RHSA-2019:0879https://access.redhat.com/errata/RHSA-2019:0935https://bugs.launchpad.net/ossa/+bug/1813007https://review.openstack.org/#/q/topic:bug/1813007https://security.openstack.org/ossa/OSSA-2019-002.htmlhttp://www.openwall.com/lists/oss-security/2019/04/09/2https://access.redhat.com/errata/RHSA-2019:0879https://access.redhat.com/errata/RHSA-2019:0935https://bugs.launchpad.net/ossa/+bug/1813007https://review.openstack.org/#/q/topic:bug/1813007https://security.openstack.org/ossa/OSSA-2019-002.html
2019-04-05
Published