------------------------------------------------------------------------- Debian LTS Advisory DLA-4735-1 [email protected] https://www.debian.org/lts/security/ Santiago Ruano Rincón August 12, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : neutron
Version : 2:21.0.0-7+deb12u1
CVE ID : CVE-2026-55707
Debian Bug : 1142937 1143170
Multiple vulnerabilities were discovered in Neutron, the OpenStack virtual
network service. These vulnerabilities were reported by Tim Shephard from
roiai.ca.
CVE-2026-55707
A project member can onboard subnets from another project's shared network
into
their own subnetpool, mutating the victim's persistent subnet state and
altering L3 routing, NAT, and address-scope behavior for victim routers.
Only
deployments with shared or RBAC-shared networks and the subnetpool
onboarding
extension enabled are affected.
Not assigned yet
A project member can read or modify another project's sub-resource by
substituting their own parent resource ID in URL used in APIs. For
conntrack helpers, deletion is also possible. The attack requires
knowing the victim's sub-resource UUID, which is a random UUIDv4 that
cannot be enumerated through the API.
For Debian 12 bookworm, this problem has been fixed in version
2:21.0.0-7+deb12u1.
We recommend that you upgrade your neutron packages.
For the detailed security status of neutron please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/neutron
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
