[openstack-announce] [OSSA 2013-008] Nova DoS by allocating all Fixed IPs (CVE-2013-1838)

Thierry Carrez thierry at openstack.org
Thu Mar 14 17:39:17 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

OpenStack Security Advisory: 2013-008
CVE: CVE-2013-1838
Date: March 14, 2013
Title: Nova DoS by allocating all Fixed IPs
Reporter: Vish Ishaya (Nebula)
Products: Nova
Affects: All versions

Description:
Vish Ishaya reported a vulnerability in Nova where there is no quota for
Fixed IPs. Previously the instance quota acted as a proxy for a Fixed IP
quota, but if your configuration allows an instance to consume more than
one Fixed IP via an extension such as multinic then this is no longer
true. Running out of Fixed IPs would result in not being able to spawn
new instances.

Grizzly (development branch) fix:
https://review.openstack.org/#/c/24451/

Folsom fix:
https://review.openstack.org/#/c/24452/

Essex fix:
https://review.openstack.org/#/c/24453/

References:
https://bugs.launchpad.net/nova/+bug/1125468
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-1838

- -- 
Thierry Carrez (ttx)
OpenStack Vulnerability Management Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCAAGBQJRQgtEAAoJEFB6+JAlsQQjf6gP/0Ao3Hq5MSChlbwtjMiUPPlC
ralE6V5l3/V/jPJ/XiHrSJo2qbwgil4SSrwj6mDx00bwj3lLyYKV9KjRx9FJjwl0
YuUm/AY1R4/miED8HyjhhteC0xAisqciwZQLrN6DwAdP3YEDZZk0Cfxp3Xw6XxAM
SAb2Gp0Ranu0lc7jLBNsp0G4idZvF232kXRDEMgpAwcsjmxh1sl97IBUqq87UJax
RDnI2p/bpPahZXBZK4RPZR92IbdVZ4SE+piC0b4ITESdxAh9NadWfUBIkf4fOdvM
yVKWFvRMhIFqTFEnpaX/091mOzkHJ8bWRpKImrw3qSLvXzyzlBwuuT0NyL6qDTPQ
0cY9gkiyqOtlvsAxF7tNDHxnIlq/zy86Tvi3KVoyJcUenGPjZwWNINhyvvFWs03t
n0W58XQOnXPxYLSI3CG5gUcJUWTbJQKQAapkoMGUASc7kcVCNv334z45Ui4n51o4
5WUOQTzgWJRskqolull7wpScaNoZtQgnnSTHwtAXt4Pykum4N3FEOEo4C/gHa1uz
nW8YkZRgoHbGYNypNDDWE6UdPZT/WOO/+RbMQwRVitFJtHzG1FuLa1fNP6mKxDPn
vpHnp9jBZlW9OjBZgp7/YqFv586l/xrT1hG3i+I6fq2w5G7Gru5PeRhUElzq4qHF
k+FvT1+nkHkvTbMb8z1z
=gipy
-----END PGP SIGNATURE-----



More information about the OpenStack-announce mailing list