SUSE-SU-2015:2220-1

    Dashboard / Vulnerabilities / SUSE-SU-2015:2220-1

    SUSE-SU-2015:2220-1

    Published: 7 Dec 2015Last Modified: 4 Feb 2026

    Summary: Security update for openstack-nova and openstack-neutron

    Details: This update for openstack-nova and openstack-neutron provides various fixes and improvements. openstack-nova: - Fix instance filtering. (bsc#927625) - Remove error messages from multipath command output before parsing. (bsc#949529) - Fix live-migration usage of the wrong connector information. - Added requirement for memcached to python-nova. (bsc#942457) - Don't expect meta attributes in object_compat that aren't in the db obj. (bsc#949070, CVE-2015-7713) - Kill rsync/scp processes before deleting instance. (bsc#935017, CVE-2015-3241) - Sync process utils from oslo for execute callbacks. (bsc#935017, CVE-2015-3241) - Fix rebuild of an instance with a volume attached. - Fixes _cleanup_rbd code to capture ImageBusy exception. - Don't try to confine a non-NUMA instance. - Include blank volumes in the block device mapping (bsc#945923) - Delete orphaned instance files from compute nodes (bsc#944178, CVE-2015-3280) openstack-neutron: - Fix usage_audit to work with ML2. - Fix UDP offloading issue with virtio VMs. (bsc#948704) - Fix ipset can't be destroyed when last rule is deleted. - Add ARP spoofing protection for LinuxBridge agent. - Don't use ARP responder for IPv6 addresses in ovs. - Stop device_owner from being set to 'network:*'. (bsc#943648, CVE-2015-5240) - NSX-mh: use router_distributed flag. - NSX-mh: Failover controller connections on socket failures. - NSX-mh: Prevent failures on router delete.

    Affected packages

    Package

    Name: openstack-neutron

    Purl: pkg:rpm/suse/openstack-neutron&distro=SUSE%20Cloud%20Compute%20Node%20for%20SUSE%20Linux%20Enterprise%2012%205

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2014.2.4~a0~dev103-10.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High