Candidate: CVE-2021-38598 PublicDate: 2021-08-23 05:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38598 https://www.openwall.com/lists/oss-security/2021/08/17/4 https://review.opendev.org/c/openstack/neutron/+/785917/ Description: OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Ubuntu-Description: Notes: mdeslaur> This issue is fixed in (2:16.4.1-0ubuntu2) in focal-updates and mdeslaur> (2:18.1.0-0ubuntu2) in hirsute-updates, but they have not yet mdeslaur> been released to -security. Mitigation: Bugs: https://launchpad.net/bugs/1938670 Priority: medium Discovered-by: Jake Yip and Justin Mammarella Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H [9.1 CRITICAL] Patches_neutron: upstream_neutron: released (2:18.1.0-2) trusty_neutron: ignored (out of standard support) trusty/esm_neutron: DNE xenial_neutron: ignored (out of standard support) esm-infra/xenial_neutron: needs-triage bionic_neutron: needs-triage focal_neutron: needed hirsute_neutron: ignored (reached end-of-life) impish_neutron: not-affected (2:18.1.0+git2021072117.147830620f-0ubuntu2) jammy_neutron: not-affected (2:18.1.0+git2021072117.147830620f-0ubuntu2) devel_neutron: not-affected (2:18.1.0+git2021072117.147830620f-0ubuntu2)