Ovn: insufficient validation of bfd packets may lead to denial of service
Published Mar 12, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.78%
Description
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Fast Datapath for RHEL 9 | affected |
|
No data.
No data.
Fast Datapath for Red Hat Enterprise Linux 8
ovn-2021-0:21.12.0-142.el8fdp
Fixed · RHSA-2024:4035
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.03-0:22.03.3-71.el8fdp
Fixed · RHSA-2024:1387
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.12-0:22.12.1-94.el8fdp
Fixed · RHSA-2024:1386
Fast Datapath for Red Hat Enterprise Linux 8
ovn23.03-0:23.03.1-100.el8fdp
Fixed · RHSA-2024:1388
Fast Datapath for Red Hat Enterprise Linux 8
ovn23.06-0:23.06.1-112.el8fdp
Fixed · RHSA-2024:1385
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.03-0:22.03.3-71.el9fdp
Fixed · RHSA-2024:1393
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.12-0:22.12.1-94.el9fdp
Fixed · RHSA-2024:1392
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.03-0:23.03.1-100.el9fdp
Fixed · RHSA-2024:1394
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.06-0:23.06.1-112.el9fdp
Fixed · RHSA-2024:1391
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.09-0:23.09.0-136.el9fdp
Fixed · RHSA-2024:1390
Fast Datapath for RHEL 7
ovn2.11
Out of support scope
Fast Datapath for RHEL 7
ovn2.12
Out of support scope
Fast Datapath for RHEL 7
ovn2.13
Out of support scope
Fast Datapath for RHEL 8
ovn2.11
Out of support scope
Fast Datapath for RHEL 8
ovn2.12
Out of support scope
Fast Datapath for RHEL 8
ovn2.13
Out of support scope
Fast Datapath for RHEL 8
ovn22.06
Out of support scope
Fast Datapath for RHEL 8
ovn22.09
Out of support scope
Fast Datapath for RHEL 9
ovn-2021
Affected
Fast Datapath for RHEL 9
ovn22.06
Out of support scope
Fast Datapath for RHEL 9
ovn22.09
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn-2021-0:21.12.0-142.el8fdp | Fixed | RHSA-2024:4035 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.03-0:22.03.3-71.el8fdp | Fixed | RHSA-2024:1387 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.12-0:22.12.1-94.el8fdp | Fixed | RHSA-2024:1386 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn23.03-0:23.03.1-100.el8fdp | Fixed | RHSA-2024:1388 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn23.06-0:23.06.1-112.el8fdp | Fixed | RHSA-2024:1385 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.03-0:22.03.3-71.el9fdp | Fixed | RHSA-2024:1393 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.12-0:22.12.1-94.el9fdp | Fixed | RHSA-2024:1392 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.03-0:23.03.1-100.el9fdp | Fixed | RHSA-2024:1394 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.06-0:23.06.1-112.el9fdp | Fixed | RHSA-2024:1391 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.09-0:23.09.0-136.el9fdp | Fixed | RHSA-2024:1390 |
| Fast Datapath for RHEL 7 | ovn2.11 | Out of support scope | n/a |
| Fast Datapath for RHEL 7 | ovn2.12 | Out of support scope | n/a |
| Fast Datapath for RHEL 7 | ovn2.13 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | ovn2.11 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | ovn2.12 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | ovn2.13 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | ovn22.06 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | ovn22.09 | Out of support scope | n/a |
| Fast Datapath for RHEL 9 | ovn-2021 | Affected | n/a |
| Fast Datapath for RHEL 9 | ovn22.06 | Out of support scope | n/a |
| Fast Datapath for RHEL 9 | ovn22.09 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (20)
- http://www.openwall.com/lists/oss-security/2024/03/12/5
- https://access.redhat.com/errata/RHSA-2024:1385 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1386 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1387 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1388 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1390 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1391 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1392 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1393 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1394 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4035 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-2182 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2267840 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/
- https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-2182
- https://www.cve.org/CVERecord?id=CVE-2024-2182
- https://www.openwall.com/lists/oss-security/2024/03/12/5
Change history (0)
No recorded changes yet.