CVE-2019-15753

Description

In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected. This occurs in PyRoute2.add() in internal/command/ip/linux/impl_pyroute2.py.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.965

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-15753 are fixed in Python-os-vif 1.15.2Windows
Vulnerabilities CVE-2019-15753 are fixed in Python-os-vif 1.17.0Windows
Vulnerabilities CVE-2019-15753 are fixed in Python-os-vif for linux 1.15.2Linux
Vulnerabilities CVE-2019-15753 are fixed in Python-os-vif for linux 1.17.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234