First published: Tue Mar 12 2024(Updated: )
Timothy Redaelli and Haresh Khandelwal discovered that Open vSwitch incorrectly handled certain crafted Geneve packets when hardware offloading via the netlink path is enabled. A remote attacker could possibly use this issue to cause Open vSwitch to crash, leading to a denial of service. (CVE-2023-3966) It was discovered that Open vSwitch incorrectly handled certain ICMPv6 Neighbor Advertisement packets. A remote attacker could possibly use this issue to redirect traffic to arbitrary IP addresses. (CVE-2023-5366)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/openvswitch-common | <3.2.2-0ubuntu0.23.10.1 | 3.2.2-0ubuntu0.23.10.1 |
Ubuntu Ubuntu | =23.10 | |
All of | ||
ubuntu/python3-openvswitch | <3.2.2-0ubuntu0.23.10.1 | 3.2.2-0ubuntu0.23.10.1 |
Ubuntu Ubuntu | =23.10 | |
All of | ||
ubuntu/openvswitch-common | <2.17.9-0ubuntu0.22.04.1 | 2.17.9-0ubuntu0.22.04.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python3-openvswitch | <2.17.9-0ubuntu0.22.04.1 | 2.17.9-0ubuntu0.22.04.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/openvswitch-common | <2.13.8-0ubuntu1.4 | 2.13.8-0ubuntu1.4 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python3-openvswitch | <2.13.8-0ubuntu1.4 | 2.13.8-0ubuntu1.4 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.