GHSA-mcpw-cp35-p3h8

Suggest an improvement
Source
https://github.com/advisories/GHSA-mcpw-cp35-p3h8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mcpw-cp35-p3h8/GHSA-mcpw-cp35-p3h8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mcpw-cp35-p3h8
Aliases
Published
2022-05-24T16:55:04Z
Modified
2024-05-02T13:27:47.154379Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
OpenStack os-vif Ageing time of 0 disables linuxbridge MAC learning
Details

In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected. This occurs in PyRoute2.add() in internal/command/ip/linux/impl_pyroute2.py.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed_at": "2024-05-02T13:11:32Z",
    "nvd_published_at": "2019-08-28T21:15:00Z",
    "severity": "CRITICAL",
    "github_reviewed": true
}
References

Affected packages

PyPI / os-vif

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.15.0
Fixed
1.15.2

Affected versions

1.*
1.15.0
1.15.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mcpw-cp35-p3h8/GHSA-mcpw-cp35-p3h8.json"

PyPI / os-vif

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.16.0
Fixed
1.17.0

Affected versions

1.*
1.16.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mcpw-cp35-p3h8/GHSA-mcpw-cp35-p3h8.json"