OSSA-2019-004: Ageing time of 0 disables linuxbridge MAC learning

Date:

August 29, 2019

CVE:

CVE-2019-15753

Affects

  • Os-vif: >=1.15.0<1.15.2, 1.16.0

Description

James Denton with Rackspace reported a vulnerability in os-vif, the Nova/Neutron network integration library. A hard-coded MAC ageing time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding for non-local destinations which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected.

Patches

Credits

  • James Denton from Rackspace (CVE-2019-15753)

References