---
title: "CVE-2019-10876\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-10876?format=md
keywords: index, follow
---

# CVE-2019-10876

Publication date 5 April 2019

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-10876?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x
before 12.0.6, and 13.x before 13.0.3. By creating two security groups with
separate/overlapping port ranges, an authenticated user may prevent Neutron
from being able to configure networks on any compute nodes where those
security groups are present, because of an Open vSwitch (OVS) firewall
KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are
affected.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| neutron | 19.04 disco | Not affected |
| 18.10 cosmic | Fixed 2:13.0.2-0ubuntu3 |
| 18.04 LTS bionic | Fixed 2:12.0.5-0ubuntu4 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-10876?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| neutron | * Upstream:   <https://review.openstack.org/648004> * Upstream:   <https://review.openstack.org/648003> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10876)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-10876)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-10876)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-10876)

### Other references

* <https://review.openstack.org/#/q/topic:bug/1813007>
* <https://www.cve.org/CVERecord?id=CVE-2019-10876>
