CVE-2015-3221: Openstack Neutron

Medium severity, CVSS 4.0. EPSS: 11.4% chance of exploitation in the next 30 days.

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

Affected products

  • Openstack Neutron: from 2014.2, before 2014.2.4 (fixed in 2014.2.4); from 2015.1.0, before 2015.1.1 (fixed in 2015.1.1)

Published 2015-08-26. Last modified 2026-06-17.