---
id: CVE-2015-3221
aliases:
  - GHSA-wf44-4mgj-rwvx
  - PYSEC-2026-856
title: OpenStack Neutron Improper Input Validation vulnerability
summary: OpenStack Neutron Improper Input Validation vulnerability
severity: medium
vendor: neutron
product: neutron
ecosystem: pip
affected:
  - neutron < 2014.2.4
  - 'neutron >= 2015.1.0, < 2015.1.1'
patched:
  - neutron 2014.2.4
  - neutron 2015.1.1
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-wf44-4mgj-rwvx'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2015-3221'
  - url: 'https://access.redhat.com/errata/RHSA-2015:1680'
  - url: 'https://access.redhat.com/security/cve/CVE-2015-3221'
  - url: 'https://bugs.launchpad.net/neutron/+bug/1461054'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1232284'
  - url: >-
      https://git.openstack.org/cgit/openstack/neutron/commit/?id=9ff6138c47c95034ba845e9448ddffd147b51f38
  - url: 'https://opendev.org/openstack/neutron'
  - url: >-
      https://web.archive.org/web/20200228084753/http://www.securityfocus.com/bid/75368
  - url: >-
      http://lists.openstack.org/pipermail/openstack-announce/2015-June/000377.html
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1680.html'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.11434
epssPercentile: 0.95871
exploitAvailable: true
ingestedAt: '2026-07-08T18:25:53.613Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-21T15:24:38.207Z'
---

## Overview

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

## Affected packages

- `neutron < 2014.2.4`
- `neutron >= 2015.1.0, < 2015.1.1`

## Remediation

Upgrade to a patched release:

- `neutron 2014.2.4`
- `neutron 2015.1.1`
