Debian dla-4735 : neutron-api - security update

high Nessus Plugin ID 334973

Synopsis

The remote Debian host is missing a security-related update.

Description

The remote Debian 12 host has packages installed that are affected by a vulnerability as referenced in the dla-4735 advisory.

------------------------------------------------------------------------- Debian LTS Advisory DLA-4735-1 [email protected] https://www.debian.org/lts/security/ Santiago Ruano Rincn August 12, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : neutron Version : 2:21.0.0-7+deb12u1 CVE ID : CVE-2026-55707 Debian Bug : 1142937 1143170

Multiple vulnerabilities were discovered in Neutron, the OpenStack virtual network service. These vulnerabilities were reported by Tim Shephard from roiai.ca.

CVE-2026-55707

A project member can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's persistent subnet state and altering L3 routing, NAT, and address-scope behavior for victim routers. Only deployments with shared or RBAC-shared networks and the subnetpool onboarding extension enabled are affected.

Not assigned yet

A project member can read or modify another project's sub-resource by substituting their own parent resource ID in URL used in APIs. For conntrack helpers, deletion is also possible. The attack requires knowing the victim's sub-resource UUID, which is a random UUIDv4 that cannot be enumerated through the API.

For Debian 12 bookworm, this problem has been fixed in version 2:21.0.0-7+deb12u1.

We recommend that you upgrade your neutron packages.

For the detailed security status of neutron please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/neutron

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Attachment:
signature.asc Description: PGP signature

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade the neutron-api packages.

See Also

https://packages.debian.org/source/bookworm/neutron

https://security-tracker.debian.org/tracker/CVE-2026-55707

https://security-tracker.debian.org/tracker/source-package/neutron

Plugin Details

Severity: High

ID: 334973

File Name: debian_DLA-4735.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/12/2026

Updated: 8/12/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.61

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-55707

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 5

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:neutron-api, p-cpe:/a:debian:debian_linux:neutron-common, p-cpe:/a:debian:debian_linux:neutron-dhcp-agent, p-cpe:/a:debian:debian_linux:neutron-doc, p-cpe:/a:debian:debian_linux:neutron-l3-agent, p-cpe:/a:debian:debian_linux:neutron-linuxbridge-agent, p-cpe:/a:debian:debian_linux:neutron-macvtap-agent, p-cpe:/a:debian:debian_linux:neutron-metadata-agent, p-cpe:/a:debian:debian_linux:neutron-metering-agent, p-cpe:/a:debian:debian_linux:neutron-openvswitch-agent, p-cpe:/a:debian:debian_linux:neutron-ovn-metadata-agent, p-cpe:/a:debian:debian_linux:neutron-plugin-nec-agent, p-cpe:/a:debian:debian_linux:neutron-rpc-server, p-cpe:/a:debian:debian_linux:neutron-server, p-cpe:/a:debian:debian_linux:neutron-sriov-agent, p-cpe:/a:debian:debian_linux:python3-neutron

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-55707