Control: tag -1 pending

Hello,

Bug #993398 in neutron reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/neutron/-/commit/8a70539dc9afdb80b2f0aac4f8e44e784729c6ab

------------------------------------------------------------------------
* CVE-2021-40085: By supplying a specially crafted extra_dhcp_opts value, an
    authenticated user may add arbitrary configuration to the dnsmasq process
    in order to crash the service, change parameters for other tenants sharing
    the same interface, or otherwise alter that daemon's behavior. This
    vulnerability may also be used to trigger a configuration parsing buffer
    overflow in versions of dnsmasq prior to 2.81, which could lead to remote
    code execution. All Neutron deployments are affected. Added upstream
    patch: Remove dhcp_extra_opt value after first newline character.
    (Closes: #993398)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/993398

Reply via email to