USN-3195-1: Nova-LXD vulnerability
10 February 2017
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Nova-LXD could allow unintended access to LXD instances over the network.
- nova-lxd - Openstack Compute - LXD container hypervisor support
James Page discovered that Nova-LXD incorrectly set up virtual network devices when creating LXD instances. This could result in an unintended firewall configuration.
The problem can be corrected by updating your system to the following package versions:
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes for new instances. However, existing instances will still be affected and must be manually updated.