USN-6690-1: Open vSwitch vulnerabilities
Timothy Redaelli and Haresh Khandelwal discovered that Open vSwitch incorrectly handled certain crafted Geneve packets when hardware offloading via the netlink path is enabled. A remote attacker could possibly use this issue to cause Open vSwitch to crash, leading to a denial of service. (CVE-2023-3966) It was discovered that Open vSwitch incorrectly handled certain ICMPv6 Neighbor Advertisement packets. A remote attacker could possibly use this issue to redirect traffic to arbitrary IP addresses. (CVE-2023-5366)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6690-1?
USN-6690-1 has been classified as a moderate severity vulnerability.
How do I fix USN-6690-1?
To resolve USN-6690-1, upgrade the affected packages to the fixed versions indicated in the advisory.
Which versions of Open vSwitch are affected by USN-6690-1?
Open vSwitch versions prior to 2.13.8-0ubuntu1.4, 2.17.9-0ubuntu0.22.04.1, and 3.2.2-0ubuntu0.23.10.1 are affected by USN-6690-1.
Who discovered the vulnerability USN-6690-1?
The vulnerability USN-6690-1 was discovered by Timothy Redaelli and Haresh Khandelwal.
What type of attack does USN-6690-1 expose Open vSwitch to?
USN-6690-1 potentially allows a remote attacker to crash Open vSwitch, leading to a denial of service.