Bug#1143170: CVE-2026-55707 / OSSA-2026-032: Subnetpool onboarding cross-project subnet mutation

Thomas Goirand <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178548047238.5306.17144655856150902720.reportbug__25696.9136231177$1785480560$gmane$org@zbuz.infomaniak.ch>
Source: neutron
Version: 2:26.0.3-0+deb13u2
Severity: grave
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-032.html


:Date: July 29, 2026
:CVE: CVE-2026-55707


Affects
~~~~~~~
- Neutron: >=14.0.0 <26.0.6, >=27.0.0 <27.0.4, >=28.0.0 <28.0.2


Description
~~~~~~~~~~~
Tim Shephard from roiai.ca reported a vulnerability in Neutron's subnetpool
onboarding API. A project member can onboard subnets from another project's
shared network into their own subnetpool, mutating the victim's persistent
subnet state and altering L3 routing, NAT, and address-scope behavior for
victim routers. Only deployments with shared or RBAC-shared networks and the
subnetpool onboarding extension enabled are affected.



Patches
~~~~~~~
- https://review.opendev.org/999134 (2025.1/epoxy)
- https://review.opendev.org/999133 (2025.2/flamingo)
- https://review.opendev.org/999132 (2026.1/gazpacho)
- https://review.opendev.org/999131 (2026.2/hibiscus (development))


Credits
~~~~~~~
- Tim Shephard from roiai.ca


References
~~~~~~~~~~
- https://launchpad.net/bugs/2152113
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55707
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.