Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 6 Aug 2013 15:05:01 +0000
From: Jeremy Stanley <>
Subject: [OSSA 2013-020] Denial of Service in Nova network source security
 groups (CVE-2013-4185)

OpenStack Security Advisory: 2013-020
CVE: CVE-2013-4185
Date: August 6, 2013
Title: Denial of Service in Nova network source security groups
Reporter: Vishvananda Ishaya (Nebula)
Products: Nova
Affects: All versions

Vishvananda Ishaya from Nebula reported a denial of service
vulnerability in Nova's handling of network source security group
policy updates. By performing a large number of server creation
operations, the proportion of updates increases quadratically and
may overwhelm nova-network such that it is no longer able to service
other requests in a timely fashion. Only setups relying on
nova-network are affected.

Havana (development branch) fix:

Grizzly fix:

Folsom fix:

This fix will be included in the havana-3 development milestone and
in a future 2013.1.3 release.


Jeremy Stanley
OpenStack Vulnerability Management Team

Download attachment "signature.asc" of type "application/pgp-signature" (967 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.