CVE-2018-14635: Openstack Neutron
Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
Affected products
- Openstack Neutron: from 11.0.0, up to and including 11.0.5; from 12.0.0, up to and including 12.0.3; version 13.0.0.0 only
- Red Hat Openstack: version 10 only; version 12 only; version 13 only
Published 2018-09-10. Last modified 2026-06-17.