UBUNTU-CVE-2019-15753

Source
https://ubuntu.com/security/CVE-2019-15753
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-15753.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-15753
Upstream
Published
2019-08-28T21:15:00Z
Modified
2025-10-24T04:47:50Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected. This occurs in PyRoute2.add() in internal/command/ip/linux/impl_pyroute2.py.

References

Affected packages

Ubuntu:20.04:LTS / python-os-vif

Package

Name
python-os-vif
Purl
pkg:deb/ubuntu/python-os-vif@2.0.0-0ubuntu2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17.0-0ubuntu1
2.*
2.0.0-0ubuntu1
2.0.0-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.0.0-0ubuntu2",
            "binary_name": "python3-os-vif"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-15753.json"

Ubuntu:22.04:LTS / python-os-vif

Package

Name
python-os-vif
Purl
pkg:deb/ubuntu/python-os-vif@2.7.1-0ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.0-0ubuntu1
2.7.0-0ubuntu1
2.7.1-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.7.1-0ubuntu1",
            "binary_name": "python3-os-vif"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-15753.json"