CVE-2022-37394

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
References
Link Resource
https://bugs.launchpad.net/ossa/+bug/1981813 Exploit Issue Tracking Third Party Advisory
https://review.opendev.org/c/openstack/nova/+/849985 Patch Third Party Advisory
https://review.opendev.org/c/openstack/nova/+/850003 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*

History

10 Aug 2022, 15:15

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
First Time Openstack nova
Openstack
CPE cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
References (MISC) https://review.opendev.org/c/openstack/nova/+/850003 - (MISC) https://review.opendev.org/c/openstack/nova/+/850003 - Third Party Advisory
References (MISC) https://review.opendev.org/c/openstack/nova/+/849985 - (MISC) https://review.opendev.org/c/openstack/nova/+/849985 - Patch, Third Party Advisory
References (MISC) https://bugs.launchpad.net/ossa/+bug/1981813 - (MISC) https://bugs.launchpad.net/ossa/+bug/1981813 - Exploit, Issue Tracking, Third Party Advisory

03 Aug 2022, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-03 07:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-37394

Mitre link : CVE-2022-37394

CVE.ORG link : CVE-2022-37394


JSON object : View

Products Affected

openstack

  • nova