Back

HIGH

Openvswitch don't match packets on nd_target field

Published Oct 6, 2023

Description

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 7 provides the `openvswitch` package only through the unsupported Optional repository. Customers are advised to install Open vSwitch (OVS) from RHEL Fast Datapath instead. Red Hat OpenStack Platform 13/16 deployments are not affected because they use openvswitch directly from the Fast Datapath channel. A rhosp-openvswitch update will therefore not be provided at this time. Any updates will be distributed through that channel.

Metrics

Weaknesses (1)

References (9)

Change history (6)
  1. MITRE
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N to CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
    • CVSS score changed from 5.5 to 7.1
  2. REDHAT
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H to CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
    • CVSS score changed from 7.1 to 5.5
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 6, 2023
Updated Feb 13, 2025
Reserved Oct 3, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 26, 2023