CVE-2018-14635

unknown
Published 2022-05-13 · Modified 2024-04-10
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-14635

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-14635.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2:13.0.0-1
debian debianbullseyefixed2:13.0.0-1
debian debianforkyfixed2:13.0.0-1
debian debiansidfixed2:13.0.0-1
debian debiantrixiefixed2:13.0.0-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIneutron>=13.0.0.0b1,<13.0.0.0b213.0.0.0b2
python PyPIneutron<11.0.611.0.6
python PyPIneutron>=12.0.0,<12.0.412.0.4

References

Verify integrity in audit chain (admin only). AS-IS.