Comment 34 for bug 1461054

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Adding 0.0.0.0/0 to allowed address pairs breaks l2 agent

Thanks for the review, we'll use Jeremy proposal in order to keep the technical details low in the description.

Can someone add series tasks for Neutron Kilo and Juno please ?

Title: Neutron L2 agent DoS through incorrect allowed address pairs
Reporter: Darragh O'Reilly (HP)
Products: Neutron
Affects: 2014.2 versions through 2014.2.3 and 2015.1.0 version

Description:
Darragh O'Reilly from HP reported a vulnerability in Neutron. By adding an address pair which is rejected as invalid by the ipset tool, an authenticated user may crash the Neutron L2 agent resulting in a denial of service attack. Neutron setups using the IPTables firewall driver are affected.