CVE Vulnerabilities

CVE-2017-5936

Published: Apr 12, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical16.04 (including)16.04 (including)
Nova-lxdUbuntuesm-infra/xenial*
Nova-lxdUbuntuxenial*

References