SB2018061413 - Denial of service in openstack-neutron 



SB2018061413 - Denial of service in openstack-neutron

Published: June 14, 2018

Security Bulletin ID SB2018061413
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2018-14635)

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The vulnerability exists due to improper IP address validation by the affected software when the Linux bridge ml2 driver is used.. A remote attacker can add a router interface to a network's subnet that includes an IP address outside the subnet's allocation pool and cause a DoS condition if the added IP address is already assigned to another system.


Remediation

Install update from vendor's website.