SUSE-SU-2019:0716-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:0716-1

    SUSE-SU-2019:0716-1

    Published: 22 Mar 2019Last Modified: 4 Feb 2026
    Upstream:

    Summary: Security update for openstack-cinder, openstack-horizon-plugin-designate-ui, openstack-neutron, openstack-neutron-lbaas

    Details: This update for openstack-cinder, openstack-horizon-plugin-designate-ui, openstack-neutron, openstack-neutron-lbaas fixes the following issues: Security vulnerabity fixed in openstack-cinder: - CVE-2017-15139: Fixed a leakage of sensitive information between tenants in certain storage volume configurations (bsc#1105476) Bug fixes and other changes in openstack-horizon-plugin-designate-ui: - Remove the py{c} files unconditionally without error messages Bug fixes and other changes in openstack-neutron: - Fixed an issue with neutron leaving behind ovs ports when already in skipped_ports (bsc#1124695) - Require version and release to ensure that subpackages are consistent and coherent (bsc#1119902) - Fixed an issue with lbass neutron ports being down or in status build (bsc#1119902) - Enable liberal TCP connection tracking to prevent connection resets (bsc#1116475) - Switch to mariadb.service - Add dependency on rabbitmq to neutron-server.service Bug fixes and changes in openstack-neutron-lbaas.changes - Improve performance of loadbalancer objects (bsc#1089834)

    Affected packages

    Package

    Name: openstack-cinder

    Purl: pkg:rpm/suse/openstack-cinder&distro=SUSE%20OpenStack%20Cloud%207

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.1.5~dev6-4.21.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High