Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
Red Hat Logo Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Troubleshooting an issue? Try Solution Engine—our new support tool.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • Español
  • Deutsch
  • Italiano
  • 한국어
  • Français
  • 日本語
  • Português
  • 中文 (中国)
  • русский
Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • JBoss Development and Management

  • JBoss Integration and Automation

  • Mobile

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Tower
  • Red Hat Ansible Engine
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat Cloud Infrastructure
  • Red Hat Cloud Suite
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat OpenShift Application Runtimes
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat JBoss Data Grid
  • Red Hat JBoss Web Server
  • Red Hat JBoss Operations Network
  • Red Hat Developer Studio
  • Red Hat JBoss Data Virtualization
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
  • Red Hat 3scale API Management
  • Red Hat Mobile Application Platform
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycle & Update Policies

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem
  • Browse Certified Solutions
  • Partner Resources

Tools

  • Solution Engine
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting
  • Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses for high-priority security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2015:1680 - Security Advisory
Issued:
2015-08-24
Updated:
2015-08-24

RHSA-2015:1680 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openstack-neutron security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated openstack-neutron packages that fix one security issue are now
available for Red Hat Enterprise Linux OpenStack Platform 6.0

Red Hat Product Security has rated this update as having a Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.

Description

OpenStack Networking (Neutron) is a pluggable, scalable, and API-driven
system that provisions networking services to virtual machines. Its main
function is to manage connectivity to and from virtual machines.

A Denial of Service flaw was found in the L2 agent when using the IPTables
firewall driver. By submitting an address pair that will be rejected as
invalid by the ipset tool, an attacker may cause the agent to crash.
(CVE-2015-3221)

Red Hat would like to thank the OpenStack upstream for reporting this
issue. Upstream acknowledges Darragh O'Reilly (HP) as the original reporter.

Additionally, the packages address the following issues:

  • Neutron failed to load multiple configuration files. The Puppet recipe
    hard-coded the --config-file parameter to a set list of configuration files
    and additional files were not loaded, even if specified. This fix creates a
    new Neutron configuration directory, /etc/neutron/conf.d, and any .conf
    files in that directory are loaded by Puppet and applied to all services.
    (BZ#1188480)
  • When configuring load balancer as a service, the Neutron configuration
    used no group as the default system user group. This group does not exist
    in the default Red Hat Enterprise Linux 7 configuration, which caused the
    virtual IP address creation to fail with the error "cannot find group id
    for 'nogroup'." (BZ#1208002)
  • Log rotation was set to one week for Neutron, but that could allow the
    log file to grow to be very large before rotating. The default log rotation
    policy has been updated to include a size limit of 10MB as well as a time
    limit to rotate daily. (BZ#1212442)
  • Previously, dnsmasq did not save lease information in persistent storage.
    When it was restarted, the lease information was lost. This behavior
    resulted from removing the '--dhcp-script' option as part of fixing
    BZ#1202392. As a result, instances were stuck in the network boot process
    for a long period of time. In addition, NACK messages were noted in the
    dnsmasq log. This update removes the authoritative option, so that NAKs are
    not sent in response to DHCPREQUESTs to other servers. This change is
    expected to prevent dnsmasq from NAKing clients renewing leases issued
    before it was restarted/rescheduled. DHCPNAK messages should no longer be
    found in the log files. (BZ#1227635)
  • Conflict tags were included in the python-neutron package spec that
    resulted in Neutron unnecessarily blocking the python-oslo-db package.
    These conflicts have been removed from the spec, so the python-oslo-db
    package can be successfully installed. (BZ#1250056)

All openstack-neutron users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenStack 6.0 x86_64

Fixes

  • BZ - 1208002 - LBASS VIP creation fails because system group "nogroup" doesn't exist
  • BZ - 1227635 - DHCPNAK after neutron-dhcp-agent restart
  • BZ - 1232284 - CVE-2015-3221 openstack-neutron: L2 agent DoS through incorrect allowed address pairs
  • BZ - 1250056 - neutron unnecessarily blocks python-oslo-db >= 1.1.0

CVEs

  • CVE-2015-3221

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenStack 6.0

SRPM
x86_64
openstack-neutron-2014.2.3-9.el7ost.noarch.rpm SHA-256: 7341dd21908690131811951a4f261c38b7ad4708f62fb75826b7b15283a9080c
openstack-neutron-bigswitch-2014.2.3-9.el7ost.noarch.rpm SHA-256: 818b42e17de8b2a687d6d3fa74dc095c891c08d76ba15aa64de244f56c09627f
openstack-neutron-brocade-2014.2.3-9.el7ost.noarch.rpm SHA-256: 21d2cf97599f18616cfa05c58eff1ea052189e328c7a1dc0fd33d8e3f7788cec
openstack-neutron-cisco-2014.2.3-9.el7ost.noarch.rpm SHA-256: d352b475d8e61f15ef2431c556a8fd44838d03c40490a7100deba8e41b49d859
openstack-neutron-common-2014.2.3-9.el7ost.noarch.rpm SHA-256: c510bf9ad7d9b3a6ba55e4fcf171d6969ad3d24fe6a859c9f283896177085f96
openstack-neutron-embrane-2014.2.3-9.el7ost.noarch.rpm SHA-256: 9e78477e03cfb20f67339a65f32d37ae3ed75eb803dcd83c8d6b58fdc69783ea
openstack-neutron-hyperv-2014.2.3-9.el7ost.noarch.rpm SHA-256: 4bd77c5743c264a4f17593cc923569d6de9eed73c997982ad468f02bab6db991
openstack-neutron-ibm-2014.2.3-9.el7ost.noarch.rpm SHA-256: c8122b9dced2c46659bdb3e8b43c0e74fb40a1bde7d7552007c11589374cb152
openstack-neutron-linuxbridge-2014.2.3-9.el7ost.noarch.rpm SHA-256: ea6e1997968c0c82b5bb2fdea8be82b43fe1cee937afb31c5c8cc7f2668be878
openstack-neutron-mellanox-2014.2.3-9.el7ost.noarch.rpm SHA-256: 1961b5324df4ee1ea12d97b02c783c268cf1627b5f83598e0f8ee44d2111322e
openstack-neutron-metaplugin-2014.2.3-9.el7ost.noarch.rpm SHA-256: d640c5dfcb7dd3e88a5ac05ad1661f8b05eb1525a39efde4866a46229ba42380
openstack-neutron-metering-agent-2014.2.3-9.el7ost.noarch.rpm SHA-256: 9ba0db494938c32be768d6c55a652761b48f2d3b02eaaa58e90742f572e7556e
openstack-neutron-midonet-2014.2.3-9.el7ost.noarch.rpm SHA-256: 88aac0a7bf10f31a7341726c00e079f4e2e07b7f7b065adf641ae8acf68c3345
openstack-neutron-ml2-2014.2.3-9.el7ost.noarch.rpm SHA-256: cb9bad32c633b5c864896e08d75670631d5149520407e8806b46446ee714a629
openstack-neutron-nec-2014.2.3-9.el7ost.noarch.rpm SHA-256: e06fbe49512d4777a279487e31c6593306db800a91abfb4e1c1be562961d3587
openstack-neutron-nuage-2014.2.3-9.el7ost.noarch.rpm SHA-256: 93cc543ec5c04b5681763fb4088f2ddf81f33d1f2f950cfcfd00982c440c30a8
openstack-neutron-ofagent-2014.2.3-9.el7ost.noarch.rpm SHA-256: e56845775eb5ee9d7490f742a559ee3fdf2bfee4c4eed6bd6fda327d5291ce87
openstack-neutron-oneconvergence-nvsd-2014.2.3-9.el7ost.noarch.rpm SHA-256: ac78b2ea8a3e8e55f33c0e1c02c58dcb15a2c906dbe94e2e28d4206032ef851b
openstack-neutron-opencontrail-2014.2.3-9.el7ost.noarch.rpm SHA-256: 78a5a4f0f67da799cef36117ca87ee169beef04808a0a2adafefbe6c287508bf
openstack-neutron-openvswitch-2014.2.3-9.el7ost.noarch.rpm SHA-256: 38857125d22f8d89347ce3df5b325ee5676c713e514c816dda1a21af21c1092e
openstack-neutron-plumgrid-2014.2.3-9.el7ost.noarch.rpm SHA-256: 6ecb81b3b9e1c4f7ef151acf065af093a10ec1d979e14f7889896c616e7b35a1
openstack-neutron-ryu-2014.2.3-9.el7ost.noarch.rpm SHA-256: ec35f2f71166f7cfda2bc717b5bffe973e8364b946eed1d2aca865c62cb07567
openstack-neutron-sriov-nic-agent-2014.2.3-9.el7ost.noarch.rpm SHA-256: 765474cfc684e7783b514deea897d927c0533105ac47b511c4039d8d6ce51643
openstack-neutron-vmware-2014.2.3-9.el7ost.noarch.rpm SHA-256: fcb602cc9d9d939ef12f1855c5e419331982b13475af9d0b8e8a20a519101168
openstack-neutron-vpn-agent-2014.2.3-9.el7ost.noarch.rpm SHA-256: 8f20d5ddc1bdfc41c928c819cf13c5597b2c74b325f50f9f7856463aea4b6e96
python-neutron-2014.2.3-9.el7ost.noarch.rpm SHA-256: 52db1d9fc78ab45c13552db8041d8834a9706c2f46337bc76b0df5121b574982

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • openshift.com
  • developers.redhat.com
  • connect.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2018 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter Facebook Google+