Lucene search

K
osvGoogleOSV:GHSA-V725-C588-H936
HistoryAug 04, 2022 - 12:00 a.m.

OpenStack Nova Changing vnic_type breaks compute service restart

2022-08-0400:00:26
Google
osv.dev
8
openstack nova
vnic_type
compute service
denial of service
sr-iov
neutron port
macvtap
authenticated user

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

3.6

Confidence

High

EPSS

0.001

Percentile

17.2%

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

3.6

Confidence

High

EPSS

0.001

Percentile

17.2%