-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security, bug fix, and enhancement update Advisory ID: RHSA-2016:1474-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2016:1474 Issue date: 2016-07-20 CVE Names: CVE-2015-8914 CVE-2016-5362 CVE-2016-5363 ==================================================================== 1. Summary: An update for openstack-neutron is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 - noarch 3. Description: OpenStack Networking (neutron) is a pluggable, scalable, and API-driven system that provisions networking services to virtual machines. Its main function is to manage connectivity to and from virtual machines. The following packages have been upgraded to a newer upstream version: openstack-neutron Security Fix(es): * Neutron functionality includes internal firewall management between networks. Due to the relaxed nature of particular rules, it is possible for machines on the same layer 2 networks to forge non-IP traffic, such as ARP and DHCP requests. (CVE-2015-8914, CVE-2016-5362, CVE-2016-5363) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1311864 - Neutron L3 Agent shows duplicate ports 1345889 - CVE-2016-5362 openstack-neutron: DHCP spoofing vulnerability 1345891 - CVE-2016-5363 openstack-neutron: MAC source address spoofing vulnerability 1345892 - CVE-2015-8914 openstack-neutron: ICMPv6 source address spoofing vulnerability 1347428 - neutron-meter-agent - makes traffic between internal networks NATed 1350400 - Rebase openstack-neutron to 2015.1.4 6. Package List: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7: Source: openstack-neutron-2015.1.4-2.el7ost.src.rpm noarch: openstack-neutron-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-bigswitch-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-brocade-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-cisco-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-common-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-embrane-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-ibm-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-linuxbridge-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-mellanox-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-metaplugin-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-metering-agent-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-midonet-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-ml2-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-nec-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-nuage-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-ofagent-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-oneconvergence-nvsd-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-opencontrail-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-openvswitch-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-ovsvapp-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-plumgrid-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-sriov-nic-agent-2015.1.4-2.el7ost.noarch.rpm openstack-neutron-vmware-2015.1.4-2.el7ost.noarch.rpm python-neutron-2015.1.4-2.el7ost.noarch.rpm python-neutron-tests-2015.1.4-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-8914 https://access.redhat.com/security/cve/CVE-2016-5362 https://access.redhat.com/security/cve/CVE-2016-5363 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXkBg5XlSAg2UNWIIRAq/gAJ9T5I7X+hD08u8CdAPArBMYg1cykACfZRdB XFm5cqHHPC4R7TcwtCdR+dg=J2xH -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
OpenStack Networking (neutron) is a pluggable, scalable, and API-driven
system that provisions networking services to virtual machines. Its main
function is to manage connectivity to and from virtual machines.
The following packages have been upgraded to a newer upstream version:
openstack-neutron
Security Fix(es):
* Neutron functionality includes internal firewall management between
networks. Due to the relaxed nature of particular rules, it is possible for
machines on the same layer 2 networks to forge non-IP traffic, such as ARP
and DHCP requests. (CVE-2015-8914, CVE-2016-5362, CVE-2016-5363)
https://access.redhat.com/security/cve/CVE-2015-8914 https://access.redhat.com/security/cve/CVE-2016-5362 https://access.redhat.com/security/cve/CVE-2016-5363 https://access.redhat.com/security/updates/classification#low
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7:
Source:
openstack-neutron-2015.1.4-2.el7ost.src.rpm
noarch:
openstack-neutron-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-bigswitch-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-brocade-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-cisco-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-common-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-embrane-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-ibm-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-linuxbridge-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-mellanox-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-metaplugin-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-metering-agent-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-midonet-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-ml2-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-nec-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-nuage-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-ofagent-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-oneconvergence-nvsd-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-opencontrail-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-openvswitch-2015.1.4-2.el7ost.noarch.rpm
openstack-neutron-ovsvapp-2015.1.4-2.el7ost.noarch.rpm
Read the Full Advisory
An update for openstack-neutron is now available for Red Hat EnterpriseLinux OpenStack Platform 7.0 (Kilo) for RHEL 7.Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 - noarch
1311864 - Neutron L3 Agent shows duplicate ports
1345889 - CVE-2016-5362 openstack-neutron: DHCP spoofing vulnerability
1345891 - CVE-2016-5363 openstack-neutron: MAC source address spoofing vulnerability
1345892 - CVE-2015-8914 openstack-neutron: ICMPv6 source address spoofing vulnerability
1347428 - neutron-meter-agent - makes traffic between internal networks NATed
1350400 - Rebase openstack-neutron to 2015.1.4
Get the latest Linux and open source security news straight to your inbox.