CVE-2022-37394

Severity
3.3LOW
EPSS
0.1%
top 81.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 3
Latest updateFeb 13

Description

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

NVDopenstack/nova24.0.024.1.2+2
PyPInova24.0.024.1.2+2
Debiannova< 2:26.0.0~rc1-3+2

Patches

🔴Vulnerability Details

4
GHSA
OpenStack Nova Changing vnic_type breaks compute service restart2022-08-04
OSV
OpenStack Nova Changing vnic_type breaks compute service restart2022-08-04
CVEList
CVE-2022-37394: An issue was discovered in OpenStack Nova before 232022-08-03
OSV
CVE-2022-37394: An issue was discovered in OpenStack Nova before 232022-08-03

📋Vendor Advisories

3
Ubuntu
Nova vulnerabilities2023-02-13
Red Hat
openstack-nova: Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap2022-08-03
Debian
CVE-2022-37394: nova - An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and...2022
CVE-2022-37394 (LOW CVSS 3.3) | An issue was discovered in OpenStac | cvebase.io