Your message dated Fri, 31 Jul 2026 07:48:48 +0000
with message-id <[email protected]>
and subject line Bug#1142937: fixed in neutron 2:28.0.1-2
has caused the Debian Bug report #1142937,
regarding Neutron sub-resource APIs do not verify parent ownership
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142937: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142937
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: neutron
Version: 2:26.0.3-0+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce:
https://wiki.openstack.org/wiki/OSSN/OSSN-0102
Neutron sub-resource APIs do not verify parent ownership
Summary:
Several Neutron APIs that operate on sub-resources (port forwardings
under floating IPs, conntrack helpers under routers) authorize the
request using the parent resource ID from the URL but load the child
resource by its own ID without verifying it belongs to that parent. A
project member can read or modify another project's sub-resource by
substituting their own parent resource ID in the URL. For conntrack
helpers, deletion is also possible. The attack requires knowing the
victim's sub-resource UUID, which is a random UUIDv4 that cannot be
enumerated through the API.
Affected Services / Software:
neutron: >=13.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0
Discussion:
The affected endpoints follow this pattern:
GET/PUT /floatingips/{fip_id}/port_forwardings/{pf_id} (DELETE is
not affected; it already validates the parent)
GET/PUT/DELETE /routers/{router_id}/conntrack_helpers/{ct_id}
Policy checks authorize against the parent (floating IP or router) from
the URL. The plugin then loads the child by bare UUID without checking
that the child's parent matches the URL parent. This allows a caller who
owns one floating IP or router to operate on port forwardings or
conntrack helpers belonging to a different project's floating IP or
router.
The mitigating factor is that the victim's sub-resource UUID cannot be
discovered through the API. The list endpoints are scoped to the
caller's own parent resources. An attacker would need to obtain the
UUID through other means.
Recommended Actions:
Upgrade Neutron to a version containing the fixes.
Patches:
The following reviews contain the fixes:
Port Forwarding (LP#2150121)
2026.2/hibiscus (development): https://review.opendev.org/989624
2026.1/gazpacho: https://review.opendev.org/990125
2025.2/flamingo: https://review.opendev.org/990126
2025.1/epoxy: https://review.opendev.org/990127
Conntrack Helpers (LP#2152109)
2026.2/hibiscus (development): https://review.opendev.org/991586
2026.1/gazpacho: https://review.opendev.org/991776
2025.2/flamingo: https://review.opendev.org/991777
2025.1/epoxy: https://review.opendev.org/991778
Credits
Tim Shephard, roiai.ca
Contacts / References
Authors: Goutham Pacha Ravi, Red Hat
This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0102
Original Launchpad bugs:
https://bugs.launchpad.net/neutron/+bug/2150121
https://bugs.launchpad.net/neutron/+bug/2152109
Mailing List : [security-sig] tag on [email protected]
OpenStack Security : https://security.openstack.org/
CVE: none
--- End Message ---
--- Begin Message ---
Source: neutron
Source-Version: 2:28.0.1-2
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
neutron, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated neutron package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 22 Jul 2026 23:12:34 +0200
Source: neutron
Architecture: source
Version: 2:28.0.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1142937 1143170
Changes:
neutron (2:28.0.1-2) unstable; urgency=medium
.
* CVE-2026-55707: subnetpool onboarding cross-project subnet mutation.
Applied upstream fix: CVE-2026-55707-stable-2026.1.patch.
(Closes: #1143170).
* Note: version already addresses OSSN-0102 (Closes: #1142937).
Checksums-Sha1:
b9cb860a9a5ece8f58fd349d878b3cacd97d55ff 4929 neutron_28.0.1-2.dsc
dc20d463785b33d7d2d5416e03d37fc50934ff4e 51652 neutron_28.0.1-2.debian.tar.xz
fea26a4b2614dda7871b200029734cc007df9e1a 22389 neutron_28.0.1-2_amd64.buildinfo
Checksums-Sha256:
9cd2ec6508aa55590640987f50a701de0aed4dd0f8e375f61837a33b854d1df4 4929
neutron_28.0.1-2.dsc
f64209914ca201f6610be60a7c4fe98003c559e2abbae0535b66308a01179b42 51652
neutron_28.0.1-2.debian.tar.xz
ef1b07bc37f43d5948c02d1ba9e4b857858394efcb5184a55f781cc54e4b8e14 22389
neutron_28.0.1-2_amd64.buildinfo
Files:
554926cfae32b6d4f1ac622b741489a7 4929 net optional neutron_28.0.1-2.dsc
436de02286d445f9c902dc2643720afb 51652 net optional
neutron_28.0.1-2.debian.tar.xz
ad164a13d73aa7d0d784e3ed13539563 22389 net optional
neutron_28.0.1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmpsTw4ACgkQ1BatFaxr
Q/5s2g/+Kv2NIARnQXPTZ+MunZXZ3gBZU3b90X6pzP7BQxPUpH5OpbtWVMKjTe81
j/6wfh7Zo+XqTU3meViPbfvarTlMVkZfAjdGZjd2ulsZR8Zq+EeSlGABOqRaZmi8
E1n5twonh+coJ5qMf3LoW+d412o/+JkMar3k2gpTo9/N0XGXCMNhTrSR2b7wWWr0
t4EHhs+cda3Vp1UTRgEhaavhaE/sTQRSqSmeqfxj1MpCqACE1Cc0V9l+nBzr1CZ7
Pgu+Q+ZfDgtyKjyp5yFVCix83U8EyQbEUR+KgQp6BkaKXG9lgqH/M53xj5jKvkza
zT9F0TgXhZFkzoFShcQegeQkgEDsXOIiD5x2xzDDzedM3hVdHwme6CEYROjqCiHA
RY8Q65FpI/aGyHYixXaQf9+zbByLbSqN/3mmfEWpc0CDSg3+w9ktRgNWWTQKLMkl
cV23E+wzNZilHp/QAS1Eg81MCFF5/QvcXAveJ9fuCEO5Nj0j4+1y187bhgmtApq7
Dt95izFWkgiJG9E20VQeC3JHlx1rMljx6bJ3ZY60GsMT0ijpUHwEe+VAK8fMre0D
a+raYR6a17OwV1VpAnkmXQt0CR5Gg48D4huyYZlZkWkV+JxE/olrO2Uu9tSU7Cdl
B652DR/xgIJQ8i5HLz0fXSYbdIYTbYm2I41cmTJWwuROyWrfDgc=
=2EZf
-----END PGP SIGNATURE-----
pgpPWZfCmGg6Z.pgp
Description: PGP signature
--- End Message ---