[OSSA 2014-019] IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167)
Bug #1309195 reported by
Baodong (Robert) Li
This bug affects 3 people
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| OpenStack Security Advisory |
Fix Released
|
High
|
Tristan Cacqueray | ||
| neutron |
Fix Released
|
Critical
|
Baodong (Robert) Li | ||
| Havana |
Fix Released
|
Critical
|
Aaron Rosen | ||
| Icehouse |
Fix Released
|
Critical
|
Aaron Rosen | ||
Bug Description
SNAT rules with IPv6 prefixes are added into the NAT table, which causes failure with the call to iptables-restore:
Stderr: "iptables-restore v1.4.18: invalid mask `64' specified\nError occurred at line: 22\nTry `iptables-restore -h' or 'iptables-restore --help' for more information.\n"
CVE References
| Changed in neutron: | |
| assignee: | nobody → Baodong (Robert) Li (baoli) |
| tags: | added: ipv6 |
| Changed in neutron: | |
| importance: | Undecided → Critical |
| Changed in ossa: | |
| status: | New → Confirmed |
| tags: | added: icehouse-backport-potential |
| Changed in ossa: | |
| importance: | Undecided → High |
| Changed in ossa: | |
| assignee: | nobody → Tristan Cacqueray (tristan-cacqueray) |
| tags: | removed: icehouse-backport-potential in-stable-havana in-stable-icehouse |
| Changed in ossa: | |
| status: | Confirmed → Triaged |
| Changed in neutron: | |
| milestone: | none → juno-1 |
| Changed in neutron: | |
| status: | Fix Committed → Fix Released |
| summary: |
- IPv6 prefix shouldn't be added in the NAT table + IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167) |
| summary: |
- IPv6 prefix shouldn't be added in the NAT table (CVE-2014-4167) + [OSSA 2014-019] IPv6 prefix shouldn't be added in the NAT table + (CVE-2014-4167) |
| Changed in ossa: | |
| status: | Triaged → Fix Committed |
| Changed in ossa: | |
| status: | Fix Committed → Fix Released |
| Changed in neutron: | |
| milestone: | juno-1 → 2014.2 |
To post a comment you must log in.

Fix proposed to branch: master /review. openstack. org/88584
Review: https:/