CVE-2023-5366: Openvswitch don't match packets on nd_target field
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
Other sources
It is possible that VMs can send ICMPv6 Neighbor Advertisement packets to mis-direct traffic to them. It needs to first send packet with correct IP address in the ndtarget field and quickly after that send packet with spoofed IP address.
Reference:
https://bugzilla.redhat.com/showbug.cgi?id=2005408
— Red Hat
Openvswitch don't match packets on ndtarget field
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openvswitchto a version that resolves this vulnerability.Fixed in 2.10.7+ds1-0+deb10u5Fixed in 2.15.0+ds1-2+deb11u5Fixed in 3.1.0-2+deb12u1Fixed in 3.3.0~git20240118.e802fe7-3Fixed in 3.3.0-1 - Upgrade
Upgrade
ubuntu/openvswitchto a version that resolves this vulnerability.Fixed in 2.13.8-0ubuntu1.4 - Upgrade
Upgrade
ubuntu/openvswitchto a version that resolves this vulnerability.Fixed in 2.17.9-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/openvswitchto a version that resolves this vulnerability.Fixed in 3.2.2-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/openvswitchto a version that resolves this vulnerability.Fixed in 3.2.2Fixed in 3.1.4Fixed in 3.0.6Fixed in 2.17.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.17.9-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.0-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2023-5366.
What is the severity of CVE-2023-5366?
The severity of CVE-2023-5366 is high.
Which software is affected by CVE-2023-5366?
Openvswitch, Redhat Openshift Container Platform, Redhat Virtualization, and Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 are affected by CVE-2023-5366.
How can a local attacker exploit CVE-2023-5366?
A local attacker can exploit CVE-2023-5366 by creating specially crafted packets with a modified or spoofed target IP address field to bypass OpenFlow rules.
Are Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 vulnerable to CVE-2023-5366?
No, Redhat Enterprise Linux versions 7.0, 8.0, and 9.0 are not vulnerable to CVE-2023-5366.