Comment 23 for bug 1837252

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: IFLA_BR_AGEING_TIME of 0 causes flooding across bridges

Thanks Gavin, James, Sean, Logan et al! Here's a final draft of the impact description; if there are no further objections I'll use it to request a CVE assignment from MITRE tomorrow:

Title: Ageing time of 0 disables linuxbridge MAC learning
Reporter: James Denton (Rackspace)
Products: os-vif
Affects: >=1.15.0<1.15.2, 1.16.0

Description:
James Denton with Rackspace reported a vulnerability in os-vif, the
Nova/Neutron network integration library. A hard-coded MAC ageing
time of 0 disables MAC learning in linuxbridge, forcing obligatory
Ethernet flooding non-local destinations which both impedes network
performance and allows users to possibly view the content of packets
for instances belonging to other tenants sharing the same network.
Only deployments using the linuxbridge backend are affected.