SUSE-SU-2019:0716-1

Source
https://www.suse.com/support/update/announcement/2019/suse-su-20190716-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:0716-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2019:0716-1
Related
Published
2019-03-22T15:10:31Z
Modified
2019-03-22T15:10:31Z
Summary
Security update for openstack-cinder, openstack-horizon-plugin-designate-ui, openstack-neutron, openstack-neutron-lbaas
Details

This update for openstack-cinder, openstack-horizon-plugin-designate-ui, openstack-neutron, openstack-neutron-lbaas fixes the following issues:

Security vulnerabity fixed in openstack-cinder:

  • CVE-2017-15139: Fixed a leakage of sensitive information between tenants in certain storage volume configurations (bsc#1105476)

Bug fixes and other changes in openstack-horizon-plugin-designate-ui:

  • Remove the py{c} files unconditionally without error messages

Bug fixes and other changes in openstack-neutron:

  • Fixed an issue with neutron leaving behind ovs ports when already in skipped_ports (bsc#1124695)
  • Require version and release to ensure that subpackages are consistent and coherent (bsc#1119902)
  • Fixed an issue with lbass neutron ports being down or in status build (bsc#1119902)
  • Enable liberal TCP connection tracking to prevent connection resets (bsc#1116475)
  • Switch to mariadb.service
  • Add dependency on rabbitmq to neutron-server.service

Bug fixes and changes in openstack-neutron-lbaas.changes

  • Improve performance of loadbalancer objects (bsc#1089834)
References

Affected packages

SUSE:OpenStack Cloud 7 / openstack-cinder

Package

Name
openstack-cinder
Purl
pkg:rpm/suse/openstack-cinder&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.1.5~dev6-4.21.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-cinder-doc

Package

Name
openstack-cinder-doc
Purl
pkg:rpm/suse/openstack-cinder-doc&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.1.5~dev6-4.21.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-horizon-plugin-designate-ui

Package

Name
openstack-horizon-plugin-designate-ui
Purl
pkg:rpm/suse/openstack-horizon-plugin-designate-ui&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.2~dev1-3.9.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-neutron

Package

Name
openstack-neutron
Purl
pkg:rpm/suse/openstack-neutron&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4.2~dev21-7.27.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-neutron-doc

Package

Name
openstack-neutron-doc
Purl
pkg:rpm/suse/openstack-neutron-doc&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4.2~dev21-7.27.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-neutron-lbaas

Package

Name
openstack-neutron-lbaas
Purl
pkg:rpm/suse/openstack-neutron-lbaas&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.2.2~dev11-4.15.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-neutron-lbaas-doc

Package

Name
openstack-neutron-lbaas-doc
Purl
pkg:rpm/suse/openstack-neutron-lbaas-doc&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.2.2~dev11-4.15.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-neutron-lbaas-agent": "9.2.2~dev11-4.15.3",
            "openstack-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-cinder-doc": "9.1.5~dev6-4.21.3",
            "openstack-cinder-scheduler": "9.1.5~dev6-4.21.3",
            "python-horizon-plugin-designate-ui": "3.0.2~dev1-3.9.3",
            "openstack-neutron-openvswitch-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-dhcp-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-l3-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron": "9.4.2~dev21-7.27.3",
            "python-neutron-lbaas": "9.2.2~dev11-4.15.3",
            "openstack-neutron-lbaas-doc": "9.2.2~dev11-4.15.3",
            "openstack-cinder-volume": "9.1.5~dev6-4.21.3",
            "openstack-neutron-doc": "9.4.2~dev21-7.27.3",
            "python-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-metadata-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-macvtap-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder-api": "9.1.5~dev6-4.21.3",
            "python-neutron": "9.4.2~dev21-7.27.3",
            "openstack-neutron-ha-tool": "9.4.2~dev21-7.27.3",
            "openstack-cinder-backup": "9.1.5~dev6-4.21.3",
            "openstack-neutron-linuxbridge-agent": "9.4.2~dev21-7.27.3",
            "openstack-neutron-metering-agent": "9.4.2~dev21-7.27.3",
            "openstack-cinder": "9.1.5~dev6-4.21.3",
            "openstack-neutron-server": "9.4.2~dev21-7.27.3"
        }
    ]
}