CVE-2022-37394
published 2022-08-03CVE-2022-37394: An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type…
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.30%
21.7th percentile
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:26.0.0~rc1-3 (bookworm) | nova 2:26.0.0~rc1-3 (bookworm) |
| openstack | nova | < 23.2.2 | 23.2.2 |
| openstack | nova | >= 0 < 2:26.0.0~rc1-3 | 2:26.0.0~rc1-3 |
| openstack | nova | >= 0 < 2:26.0.0~rc1-3 | 2:26.0.0~rc1-3 |
| openstack | nova | >= 0 < 2:26.0.0~rc1-3 | 2:26.0.0~rc1-3 |
| openstack | nova | >= 0 < 23.2.2 | 23.2.2 |
| openstack | nova | >= 0 < 2:17.0.13-0ubuntu5.3 | 2:17.0.13-0ubuntu5.3 |
| openstack | nova | >= 0 < 2:21.2.4-0ubuntu2.2 | 2:21.2.4-0ubuntu2.2 |
| openstack | nova | >= 0 < 2:13.1.4-0ubuntu4.5+esm1 | 2:13.1.4-0ubuntu4.5+esm1 |
| openstack | nova | >= 24.0.0 < 24.1.2 | 24.1.2 |
| openstack | nova | >= 24.0.0 < 24.1.2 | 24.1.2 |
| openstack | nova | >= 25.0.0 < 25.0.2 | 25.0.2 |
| openstack | nova | >= 25.0.0 < 25.0.2 | 25.0.2 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
nova vulnerabilities
osv·2023-02-13·CVSS 3.3
CVE-2015-9543 [LOW] nova vulnerabilities
nova vulnerabilities
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service attack. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-1
GHSA
OpenStack Nova Changing vnic_type breaks compute service restart
ghsa·2022-08-04
CVE-2022-37394 [LOW] OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
OSV
OpenStack Nova Changing vnic_type breaks compute service restart
osv·2022-08-04
CVE-2022-37394 [LOW] OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
OSV
CVE-2022-37394: An issue was discovered in OpenStack Nova before 23
osv·2022-08-03·CVSS 3.3
CVE-2022-37394 [LOW] CVE-2022-37394: An issue was discovered in OpenStack Nova before 23
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2023-02-13·CVSS 3.3
CVE-2021-3654 [LOW] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Several security issues were fixed in Nova.
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service a
Red Hat
openstack-nova: Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap
vendor_redhat·2022-08-03·CVSS 3.3
CVE-2022-37394 [LOW] CWE-400 openstack-nova: Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap
openstack-nova: Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
Package: openstack-nova (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Package: openstack-nova (Red Hat OpenStack Platform 16.1) - Fix deferred
Package: openstack-nova (Red Hat OpenStack Platform 17.0) - Out of support scope
Debian
CVE-2022-37394: nova - An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and...
vendor_debian·2022·CVSS 3.3
CVE-2022-37394 [LOW] CVE-2022-37394: nova - An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and...
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
Scope: local
bookworm: resolved (fixed in 2:26.0.0~rc1-3)
bullseye: open
forky: resolved (fixed in 2:26.0.0~rc1-3)
sid: resolved (fixed in 2:26.0.0~rc1-3)
trixie: resolved (fixed in 2:26.0.0~rc1-3)
No detection rules found.
No public exploits indexed.
2022-08-03
Published