UBUNTU-CVE-2022-37394
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-37394
UBUNTU-CVE-2022-37394
Summary:
Details: An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
References: https://ubuntu.com/security/CVE-2022-37394, https://review.opendev.org/c/openstack/nova/+/849985, https://review.opendev.org/c/openstack/nova/+/850003, https://ubuntu.com/security/notices/USN-5866-1, https://www.cve.org/CVERecord?id=CVE-2022-37394
Affected packages
Package
Name: nova
Purl: pkg:deb/ubuntu/nova@2:21.2.4-0ubuntu2.2?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
