Format: 1.8 Date: Tue, 26 Sep 2023 13:09:38 +0000 Source: neutron Binary: neutron-common neutron-dhcp-agent neutron-l3-agent neutron-linuxbridge-agent neutron-macvtap-agent neutron-metadata-agent neutron-metering-agent neutron-openvswitch-agent neutron-plugin-linuxbridge-agent neutron-plugin-ml2 neutron-plugin-openvswitch-agent neutron-plugin-sriov-agent neutron-server neutron-sriov-agent python-neutron Architecture: source Version: 2:12.1.1-0ubuntu8.1~cloud0 Distribution: xenial Urgency: medium Maintainer: Ubuntu Developers Changed-By: Openstack Ubuntu Testing Bot Description: neutron-common - Neutron is a virtual network service for Openstack - common neutron-dhcp-agent - Neutron is a virtual network service for Openstack - DHCP agent neutron-l3-agent - Neutron is a virtual network service for Openstack - l3 agent neutron-linuxbridge-agent - Neutron is a virtual network service for Openstack - linuxbridge neutron-macvtap-agent - Neutron is a virtual network service for Openstack - Macvtap L2 A neutron-metadata-agent - Neutron is a virtual network service for Openstack - metadata age neutron-metering-agent - Neutron is a virtual network service for Openstack - metering age neutron-openvswitch-agent - Neutron is a virtual network service for Openstack - Open vSwitch neutron-plugin-linuxbridge-agent - Transitional package for neutron-linuxbridge-agent neutron-plugin-ml2 - Neutron is a virtual network service for Openstack - ML2 plugin neutron-plugin-openvswitch-agent - Transitional package for neutron-openvswitch-agent neutron-plugin-sriov-agent - Transitional package for neutron-sriov-agent neutron-server - Neutron is a virtual network service for Openstack - server neutron-sriov-agent - Neutron is a virtual network service for Openstack - SR-IOV agent python-neutron - Neutron is a virtual network service for Openstack - Python libra Changes: neutron (2:12.1.1-0ubuntu8.1~cloud0) xenial-queens; urgency=medium . * New update for the Ubuntu Cloud Archive. . neutron (2:12.1.1-0ubuntu8.1) bionic-security; urgency=medium . * SECURITY UPDATE: IPv6 impersonation in Open vSwitch firewall rules - debian/patches/CVE-2021-20267-1.patch: allow egress ICMPv6 only for known addresses in doc/source/contributor/internals/openvswitch_firewall.rst, neutron/agent/linux/openvswitch_firewall/firewall.py, neutron/tests/unit/agent/linux/openvswitch_firewall/test_firewall.py. - debian/patches/CVE-2021-20267-2.patch: restrict IPv6 NA and DHCP(v6) IP and MAC source addresses in neutron/agent/firewall.py, neutron/agent/linux/openvswitch_firewall/firewall.py, neutron/tests/unit/agent/linux/openvswitch_firewall/test_firewall.py. - CVE-2021-20267 * SECURITY UPDATE: hardware address impersonation with ebtables-nft - debian/patches/CVE-2021-38598.patch: make ARP protection commands compatible with "ebtables-nft" in neutron/plugins/ml2/drivers/linuxbridge/agent/arp_protect.py, neutron/tests/unit/plugins/ml2/drivers/linuxbridge/agent/test_arp_protect.py. - CVE-2021-38598 * SECURITY UPDATE: dnsmasq reconfiguration issue - debian/patches/CVE-2021-40085.patch: remove dhcp_extra_opt value after first newline character in neutron/agent/linux/dhcp.py, neutron/tests/unit/agent/linux/test_dhcp.py. - CVE-2021-40085 * SECURITY UPDATE: memory consumption via API requests - debian/patches/CVE-2021-40797.patch: don't use singleton in routes.middleware.RoutesMiddleware in neutron/api/extensions.py. - CVE-2021-40797 * SECURITY UPDATE: uncontrolled resource consumption flaw - debian/patches/CVE-2022-3277.patch: do not allow a tenant to create a default SG for another one in neutron/db/securitygroups_db.py, neutron/tests/unit/db/test_securitygroups_db.py. - CVE-2022-3277 Checksums-Sha1: 79549bd6a9a689fa0b71875e0efd490e79b68a23 5163 neutron_12.1.1-0ubuntu8.1~cloud0.dsc 0113d56e2af27c35da92e6500a60154a59bc7590 10486801 neutron_12.1.1.orig.tar.gz 613c875ab75e519bff5f8ef12e61bf53048baebb 50252 neutron_12.1.1-0ubuntu8.1~cloud0.debian.tar.xz Checksums-Sha256: 9891b7c48cf1f2c629a07c23309f43673a5625e47102e0e062afaeaa0fb20e87 5163 neutron_12.1.1-0ubuntu8.1~cloud0.dsc 4be6ecdb3a258fc829d289ea2e3b60dce49e4b90a93b153b70c4948eb4968602 10486801 neutron_12.1.1.orig.tar.gz d25195681b0fd02a0939e329cc19084be746f8752145083c5bb38ed00166d8e5 50252 neutron_12.1.1-0ubuntu8.1~cloud0.debian.tar.xz Files: ab8ef8acf453b8bdf4dafd81e8b2a2db 5163 net optional neutron_12.1.1-0ubuntu8.1~cloud0.dsc 6a50960794da997c1fb06754eaa1c863 10486801 net optional neutron_12.1.1.orig.tar.gz 4a528850138b5a7612c8d43458d665a1 50252 net optional neutron_12.1.1-0ubuntu8.1~cloud0.debian.tar.xz Original-Maintainer: Chuck Short