USN-6514-1: Open vSwitch vulnerability
Published Nov 26, 2023
·Updated
It was discovered that Open vSwitch did not correctly handle OpenFlow rules for ICMPv6 Neighbour Advertisement packets. A local attacker could possibly use this issue to redirect traffic to arbitrary IP addresses.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/openvswitch-common<2.13.8-0ubuntu1.3
2.13.8-0ubuntu1.3
Ubuntu Ubuntu=20.04
All of the following
ubuntu/openvswitch-common<2.9.8-0ubuntu0.18.04.5+esm1
2.9.8-0ubuntu0.18.04.5+esm1
Ubuntu Ubuntu=18.04
Event History
Nov 26, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of this Open vSwitch vulnerability?
The vulnerability ID is USN-6514-1.
2
What is the impact of the Open vSwitch vulnerability?
The vulnerability allows a local attacker to redirect traffic to arbitrary IP addresses.
3
How can a local attacker exploit this Open vSwitch vulnerability?
The local attacker can exploit the vulnerability by manipulating OpenFlow rules for ICMPv6 Neighbour Advertisement packets.
4
Which versions of Open vSwitch are affected by this vulnerability?
The versions affected are openvswitch-common 2.13.8-0ubuntu1.3 and openvswitch-common 2.9.8-0ubuntu0.18.04.5+esm1.
5
How do I fix the Open vSwitch vulnerability?
To fix the vulnerability, update to version 2.13.8-0ubuntu1.3 for Ubuntu 20.04 or version 2.9.8-0ubuntu0.18.04.5+esm1 for Ubuntu 18.04.