First published: Wed Sep 20 2023(Updated: )
NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Cumulus Linux | <5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-25525.
The severity of CVE-2023-25525 is high with a severity value of 7.5.
The affected software is NVIDIA Cumulus Linux up to version 5.6.0.
CVE-2023-25525 is a vulnerability in NVIDIA Cumulus Linux where a VxLAN-encapsulated IPv6 packet received on an SVI interface may be incorrectly forwarded, leading to information disclosure.
To fix CVE-2023-25525, update NVIDIA Cumulus Linux to a version higher than 5.6.0.