CVE-2015-8914: OpenStack Neutron allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism
(updated )
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.
References
- access.redhat.com/errata/RHSA-2016:1473
- access.redhat.com/errata/RHSA-2016:1474
- bugs.launchpad.net/neutron/+bug/1502933
- github.com/advisories/GHSA-3vj4-cvjp-482h
- github.com/openstack/neutron
- github.com/openstack/neutron/commit/1d1159bb2b57f0b4193f8666f53736f05bf7eac9
- github.com/openstack/neutron/commit/3e66b1a87544d7a127abceec13bfeacb8f18f7e1
- nvd.nist.gov/vuln/detail/CVE-2015-8914
- review.openstack.org/
- review.openstack.org/
- review.openstack.org/
- security.openstack.org/ossa/OSSA-2016-009.html
Code Behaviors & Features
Detect and mitigate CVE-2015-8914 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →