CVE-2023-5366: Openvswitch don't match packets on nd_target field

Published Sep 21, 2021
·
Updated

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

Other sources

It is possible that VMs can send ICMPv6 Neighbor Advertisement packets to mis-direct traffic to them. It needs to first send packet with correct IP address in the ndtarget field and quickly after that send packet with spoofed IP address.

Reference:

https://bugzilla.redhat.com/showbug.cgi?id=2005408

Red Hat

Openvswitch don't match packets on ndtarget field

Microsoft

Affected Software

19 affected componentsFixes available
debian/openvswitch<=2.10.7+ds1-0+deb10u1, <=2.15.0+ds1-2+deb11u4, <=3.1.0-2
2.10.7+ds1-0+deb10u52.15.0+ds1-2+deb11u53.1.0-2+deb12u13.3.0~git20240118.e802fe7-33.3.0-1
ubuntu/openvswitch<2.13.8-0ubuntu1.4
2.13.8-0ubuntu1.4
ubuntu/openvswitch<2.17.9-0ubuntu0.22.04.1
2.17.9-0ubuntu0.22.04.1
ubuntu/openvswitch<3.2.2-0ubuntu0.23.10.1
3.2.2-0ubuntu0.23.10.1
ubuntu/openvswitch<3.2.2, <3.1.4, <3.0.6, <2.17.9
3.2.23.1.43.0.62.17.9
Openvswitch OpenvSwitch<2023-02-28
redhat OpenShift Container Platform=4.0
redhat Virtualization=4.0
redhat Enterprise Linux=7.0
All of the following
redhat Fast Datapath
Any of the following
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Fast Datapath
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Microsoft cbl2 openvswitch 2.17.9-1<2.17.9-1
2.17.9-1
Microsoft azl3 openvswitch 3.3.0-1<3.3.0-1
3.3.0-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openvswitch to a version that resolves this vulnerability.

    Fixed in 2.10.7+ds1-0+deb10u5Fixed in 2.15.0+ds1-2+deb11u5Fixed in 3.1.0-2+deb12u1Fixed in 3.3.0~git20240118.e802fe7-3Fixed in 3.3.0-1
  2. Upgrade

    Upgrade ubuntu/openvswitch to a version that resolves this vulnerability.

    Fixed in 2.13.8-0ubuntu1.4
  3. Upgrade

    Upgrade ubuntu/openvswitch to a version that resolves this vulnerability.

    Fixed in 2.17.9-0ubuntu0.22.04.1
  4. Upgrade

    Upgrade ubuntu/openvswitch to a version that resolves this vulnerability.

    Fixed in 3.2.2-0ubuntu0.23.10.1
  5. Upgrade

    Upgrade ubuntu/openvswitch to a version that resolves this vulnerability.

    Fixed in 3.2.2Fixed in 3.1.4Fixed in 3.0.6Fixed in 2.17.9
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.17.9-1
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 3.3.0-1

Event History

Sep 21, 2021
Data Sourced
via Red Hat·02:07 PM
DescriptionSeverityAffected Software
Oct 6, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionSeverityWeakness
Mar 28, 2024
Data Sourced
via Launchpad·01:56 PM
Description
Oct 2, 2025
Data Sourced
via Microsoft·06:11 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·06:11 AM
Affected Software
Updated
via Microsoft·06:11 AM
DescriptionSeverity

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this flaw?

The vulnerability ID for this flaw is CVE-2023-5366.

2

What is the severity of CVE-2023-5366?

The severity of CVE-2023-5366 is high.

3

Which software is affected by CVE-2023-5366?

Openvswitch, Redhat Openshift Container Platform, Redhat Virtualization, and Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 are affected by CVE-2023-5366.

4

How can a local attacker exploit CVE-2023-5366?

A local attacker can exploit CVE-2023-5366 by creating specially crafted packets with a modified or spoofed target IP address field to bypass OpenFlow rules.

5

Are Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 vulnerable to CVE-2023-5366?

No, Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 are not vulnerable to CVE-2023-5366.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203