CVE-2019-9735
published 2019-03-13CVE-2019-9735: An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
3.64%
88.3th percentile
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | neutron | < neutron 2:13.0.2-13 (bookworm) | neutron 2:13.0.2-13 (bookworm) |
| openstack | neutron | < 10.0.8 | 10.0.8 |
| openstack | neutron | >= 0 < 2:13.0.2-13 | 2:13.0.2-13 |
| openstack | neutron | >= 0 < 2:13.0.2-13 | 2:13.0.2-13 |
| openstack | neutron | >= 0 < 2:13.0.2-13 | 2:13.0.2-13 |
| openstack | neutron | >= 0 < 2:13.0.2-13 | 2:13.0.2-13 |
| openstack | neutron | >= 0 < 10.0.8 | 10.0.8 |
| openstack | neutron | >= 11.0.0 < 11.0.7 | 11.0.7 |
| openstack | neutron | >= 11.0.0 < 11.0.7 | 11.0.7 |
| openstack | neutron | >= 12.0.0 < 12.0.6 | 12.0.6 |
| openstack | neutron | >= 12.0.0 < 12.0.6 | 12.0.6 |
| openstack | neutron | >= 13.0.0 < 13.0.3 | 13.0.3 |
| openstack | neutron | >= 13.0.0 < 13.0.3 | 13.0.3 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Neutron vulnerability
vendor_ubuntu·2019-06-25
CVE-2019-9735 OpenStack Neutron vulnerability
Title: OpenStack Neutron vulnerability
Summary: A system hardening measure could be bypassed.
Erik Olof Gunnar Andersson discovered that OpenStack Neutron incorrectly
handled certain security group rules in the iptables firewall module. An
authenticated attacker could possibly use this issue to block further
application of security group rules for other instances.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-neutron: incorrect validation of port settings in iptables security group driver
vendor_redhat·2019-03-03·CVSS 6.5
CVE-2019-9735 [MEDIUM] CWE-20 openstack-neutron: incorrect validation of port settings in iptables security group driver
openstack-neutron: incorrect validation of port settings in iptables security group driver
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
A validation flaw was discovered in the iptables firewall module in OpenStack Neutron. By setting a destination port in a security group rule, along with a protocol that does not support t
Debian
CVE-2019-9735: neutron - An issue was discovered in the iptables firewall module in OpenStack Neutron bef...
vendor_debian·2019·CVSS 6.5
CVE-2019-9735 [MEDIUM] CVE-2019-9735: neutron - An issue was discovered in the iptables firewall module in OpenStack Neutron bef...
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
Scope: local
bookworm: resolved (fixed in 2:13.0.2-13)
bullseye: resolved (fixed in 2:13.0.2-13)
forky: resolved (fixed in 2:13.0.2-13)
sid: resolved (fixed in 2:13.0.2-13)
trixie: resolved (fixed in 2:13.0.2-13)
GHSA
OpenStack Neutron's unsupported dport option prevents applying security groups
ghsa·2022-05-13
CVE-2019-9735 [HIGH] CWE-755 OpenStack Neutron's unsupported dport option prevents applying security groups
OpenStack Neutron's unsupported dport option prevents applying security groups
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
OSV
OpenStack Neutron's unsupported dport option prevents applying security groups
osv·2022-05-13
CVE-2019-9735 [HIGH] OpenStack Neutron's unsupported dport option prevents applying security groups
OpenStack Neutron's unsupported dport option prevents applying security groups
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
OSV
CVE-2019-9735: An issue was discovered in the iptables firewall module in OpenStack Neutron before 10
osv·2019-03-13·CVSS 6.5
CVE-2019-9735 [MEDIUM] CVE-2019-9735: An issue was discovered in the iptables firewall module in OpenStack Neutron before 10
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver [openstack-rdo]
bugzilla·2019-03-20·CVSS 6.5
CVE-2019-9735 [MEDIUM] CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver [openstack-rdo]
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discu
Bugzilla
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver
bugzilla·2019-03-20·CVSS 6.5
CVE-2019-9735 [MEDIUM] CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
Reference:
https://bugs.launchpad.net/neutron/+bug/1818385
https://seclists.org/oss-sec/2019/q1/183
Upstream commit:
https://git.openstack.org/cgit/openstack/neutron/commit
Bugzilla
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver (OSSA-2019-001) [openstack-10]
bugzilla·2019-03-19·CVSS 6.5
CVE-2019-9735 [MEDIUM] CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver (OSSA-2019-001) [openstack-10]
CVE-2019-9735 openstack-neutron: incorrect validation of port settings in iptables security group driver (OSSA-2019-001) [openstack-10]
Cloned from launchpad bug 1818385.
Description:
This command should be invalid, but Neutron (Rocky) allows it to be created.
> openstack security group rule create xxx --protocol vrrp --ingress --remote-ip --dst-port 112
Since iptables does not allow dst-port being passed. It would trigger the following error on the compute and fail to apply any future iptable rules.
> unknown option "--dport"
Specification URL (additional information):
https://bugs.launchpad.net/neutron/+bug/1818385
Discussion:
Adding this as a security tracker to the CVE flaw, 1690745.
---
Changed the Summary syntax so that this can be recognized as a security bug.
---
Since
http://www.openwall.com/lists/oss-security/2019/03/18/2http://www.securityfocus.com/bid/107390https://access.redhat.com/errata/RHSA-2019:0879https://access.redhat.com/errata/RHSA-2019:0916https://access.redhat.com/errata/RHSA-2019:0935https://launchpad.net/bugs/1818385https://seclists.org/bugtraq/2019/Mar/24https://security.openstack.org/ossa/OSSA-2019-001.htmlhttps://usn.ubuntu.com/4036-1/https://www.debian.org/security/2019/dsa-4409http://www.openwall.com/lists/oss-security/2019/03/18/2http://www.securityfocus.com/bid/107390https://access.redhat.com/errata/RHSA-2019:0879https://access.redhat.com/errata/RHSA-2019:0916https://access.redhat.com/errata/RHSA-2019:0935https://launchpad.net/bugs/1818385https://seclists.org/bugtraq/2019/Mar/24https://security.openstack.org/ossa/OSSA-2019-001.htmlhttps://usn.ubuntu.com/4036-1/https://www.debian.org/security/2019/dsa-4409
2019-03-13
Published