PT-2022-23970 · Openstack+4 · Openstack Nova+4

Balazs Gibizer

·

Published

2022-08-03

·

Updated

2024-08-02

·

CVE-2022-37394

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenStack Nova versions prior to 23.2.2 OpenStack Nova versions 24.x prior to 24.1.2 OpenStack Nova versions 25.x prior to 25.0.2
Description An issue was discovered in OpenStack Nova where an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. This can be achieved by creating a neutron port with the direct vnic type, creating an instance bound to that port, and then changing the vnic type of the bound port to macvtap. Only Nova deployments configured with SR-IOV are affected.
Recommendations For OpenStack Nova versions prior to 23.2.2, update to version 23.2.2 or later. For OpenStack Nova versions 24.x prior to 24.1.2, update to version 24.1.2 or later. For OpenStack Nova versions 25.x prior to 25.0.2, update to version 25.0.2 or later. As a temporary workaround, consider restricting the ability to change the vnic type of bound ports to prevent the compute service from failing to restart.

Exploit

Fix

Related Identifiers

ALT-PU-2024-1074
ALT-PU-2024-9720
CVE-2022-37394
GHSA-V725-C588-H936
RHSA-2023:1948
USN-5866-1

Affected Products

Alt Linux
Debian
Linuxmint
Openstack Nova
Ubuntu