Comment 17 for bug 1837252

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: IFLA_BR_AGEING_TIME of 0 causes flooding across bridges

Thanks Logan! So how about this:

Title: Ageing time of 0 disables linuxbridge MAC learning
Reporter: James Denton
Products: os-vif
Affects: >=1.12.0<1.15.2, 1.16.0

Description:
James Denton reported a vulnerability in os-vif, the Nova/Neutron
network integration library. The hard-coded MAC ageing time of 0
disables MAC learning in linuxbridge, forcing obligatory
Ethernet flooding which both slows network performance significantly
and allows users to possibly view the content of packets for
instances belonging to other tenants sharing the same network.
Only deployments using the linuxbridge backend are affected.