English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

OpenStack Compute (Nova) iptables Resource Exhaustion Denial of Service Vulnerability


Secunia ID

SA49034

CVE-ID

CVE-2012-2101

Release Date

30 Apr 2012

Criticality

Less Critical

Solution Status

Vendor Workaround

Software

OpenStack Compute (Nova) 2012.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in OpenStack Compute (Nova), which can be exploited by malicious users to cause a DoS (Denial of Service).

The vulnerability is caused due to the application not enforcing quotas on the number of security group rules created. This can be exploited to create multiple iptables rules and exhaust system resources.

The vulnerability is reported in version 2012.1. Other versions may also be affected.

Solution

Fixed in the GIT repository.

Reported by

Red Hat credits Dan Prince.

Original Advisory

https://bugs.launchpad.net/nova/+bug/969545