Your submission was sent successfully! Close

CVE-2017-5936

Published: 8 February 2017

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
nova-lxd
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist

upstream Needs triage

xenial
Released (13.2.0-0ubuntu1.16.04.1)
yakkety Not vulnerable
(only affects Mitaka release)