[OSSA-2019-004] Ageing time of 0 disables linuxbridge MAC learning (CVE-2019-15753)

Related Vulnerabilities: CVE-2019-15753  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
[OSSA-2019-004] Ageing time of 0 disables linuxbridge MAC learning (CVE-2019-15753)

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Jeremy Stanley &lt;fungi () yuggoth org&gt;

Date: Thu, 29 Aug 2019 14:42:44 +0000

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
=================================================================
OSSA-2019-004: Ageing time of 0 disables linuxbridge MAC learning
=================================================================

:Date: August 29, 2019
:CVE: CVE-2019-15753

Affects
~~~~~~~
- Os-vif: &gt;=1.15.0&lt;1.15.2, 1.16.0

Description
~~~~~~~~~~~
James Denton with Rackspace reported a vulnerability in os-vif, the
Nova/Neutron network integration library. A hard-coded MAC ageing
time
of 0 disables MAC learning in linuxbridge, forcing obligatory
Ethernet
flooding for non-local destinations which both impedes network
performance and allows users to possibly view the content of packets
for instances belonging to other tenants sharing the same network.
Only deployments using the linuxbridge backend are affected.

Patches
~~~~~~~
- https://review.opendev.org/678098 (Stein)
- https://review.opendev.org/672834 (Train)

Credits
~~~~~~~
- James Denton from Rackspace (CVE-2019-15753)

References
~~~~~~~~~~
- https://launchpad.net/bugs/1837252
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15753

-- 
Jeremy Stanley, on behalf of the OpenStack VMT
Attachment:
signature.asc
Description: 

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

[OSSA-2019-004] Ageing time of 0 disables linuxbridge MAC learning (CVE-2019-15753) Jeremy Stanley (Aug 29)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->