VulnerabilityModified
CVE-2017-5936
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
HIGH 7.5EPSS 2.93%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.93% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu linux · openstack/nova-lxd
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/02/09/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/96182Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3195-1Third Party Advisory
- https://bugs.launchpad.net/nova-lxd/+bug/1656847Issue Tracking, Patch, Third Party Advisory
- https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2Issue Tracking, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/09/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/96182Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3195-1Third Party Advisory
- https://bugs.launchpad.net/nova-lxd/+bug/1656847Issue Tracking, Patch, Third Party Advisory
- https://github.com/openstack/nova-lxd/commit/1b76cefb92081efa1e88cd8f330253f857028bd2Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.