Comment 17 for bug 1939733

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Remote Code Execution via extra_dhcp_opts

Okay, this is what I'll use to request a CVE assignment from MITRE. Once viable backports for stable/wallaby, stable/victoria, and stable/ussuri branches are attached, I'll schedule a disclosure date and prepare notification under embargo for our downstream stakeholders...

Title: Arbitrary dnsmasq reconfiguration via extra_dhcp_opts
Reporter: Pavel Toporkov
Products: Neutron
Affects: <16.4.1, >=17.0.0 <17.2.1, >=18.0.0 <18.1.1

Description:
Pavel Toporkov reported a vulnerability in Neutron. By supplying a specially crafted extra_dhcp_opts value, an authenticated user may add arbitrary configuration to the dnsmasq process in order to crash the service, change parameters for other tenants sharing the same interface, or otherwise alter that daemon's behavior. This vulnerability may also be used to trigger a configuration parsing buffer overflow in versions of dnsmasq prior to 2.81, which could lead to remote code execution. All Neutron deployments are affected.