Ovn: egress acls may be bypassed via specially crafted udp packet
Published Jan 23, 2025
8.1
HIGHCVSS 3.1
EPSS 0.86%
Description
A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
No data.
No data.
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.03-0:22.03.7-11.el8fdp
Fixed · RHSA-2025:1083
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.06-0:22.06.0-273.el8fdp
Fixed · RHSA-2025:1084
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.09-0:22.09.2-86.el8fdp
Fixed · RHSA-2025:1085
Fast Datapath for Red Hat Enterprise Linux 8
ovn22.12-0:22.12.1-107.el8fdp
Fixed · RHSA-2025:1086
Fast Datapath for Red Hat Enterprise Linux 8
ovn23.03-0:23.03.3-22.el8fdp
Fixed · RHSA-2025:1087
Fast Datapath for Red Hat Enterprise Linux 8
ovn23.06-0:23.06.4-26.el8fdp
Fixed · RHSA-2025:1088
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.03-0:22.03.7-11.el9fdp
Fixed · RHSA-2025:1089
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.06-0:22.06.0-273.el9fdp
Fixed · RHSA-2025:1090
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.09-0:22.09.2-86.el9fdp
Fixed · RHSA-2025:1091
Fast Datapath for Red Hat Enterprise Linux 9
ovn22.12-0:22.12.1-107.el9fdp
Fixed · RHSA-2025:1092
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.03-0:23.03.3-22.el9fdp
Fixed · RHSA-2025:1093
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.06-0:23.06.4-26.el9fdp
Fixed · RHSA-2025:1094
Fast Datapath for Red Hat Enterprise Linux 9
ovn23.09-0:23.09.6-12.el9fdp
Fixed · RHSA-2025:1095
Fast Datapath for Red Hat Enterprise Linux 9
ovn24.03-0:24.03.4-53.el9fdp
Fixed · RHSA-2025:1096
Fast Datapath for Red Hat Enterprise Linux 9
ovn24.09-0:24.09.1-66.el9fdp
Fixed · RHSA-2025:1097
Red Hat OpenShift Container Platform 4
ovn22.06
Out of support scope
Red Hat OpenShift Container Platform 4
ovn22.09
Out of support scope
Red Hat OpenShift Container Platform 4
ovn22.12
Out of support scope
Red Hat OpenShift Container Platform 4
ovn23.03
Out of support scope
Red Hat OpenShift Container Platform 4
ovn23.06
Will not fix
Red Hat OpenShift Container Platform 4
ovn23.09
Not affected
Red Hat OpenShift Container Platform 4
ovn24.03
Not affected
Red Hat OpenShift Container Platform 4
ovn24.09
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.03-0:22.03.7-11.el8fdp | Fixed | RHSA-2025:1083 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.06-0:22.06.0-273.el8fdp | Fixed | RHSA-2025:1084 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.09-0:22.09.2-86.el8fdp | Fixed | RHSA-2025:1085 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn22.12-0:22.12.1-107.el8fdp | Fixed | RHSA-2025:1086 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn23.03-0:23.03.3-22.el8fdp | Fixed | RHSA-2025:1087 |
| Fast Datapath for Red Hat Enterprise Linux 8 | ovn23.06-0:23.06.4-26.el8fdp | Fixed | RHSA-2025:1088 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.03-0:22.03.7-11.el9fdp | Fixed | RHSA-2025:1089 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.06-0:22.06.0-273.el9fdp | Fixed | RHSA-2025:1090 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.09-0:22.09.2-86.el9fdp | Fixed | RHSA-2025:1091 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn22.12-0:22.12.1-107.el9fdp | Fixed | RHSA-2025:1092 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.03-0:23.03.3-22.el9fdp | Fixed | RHSA-2025:1093 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.06-0:23.06.4-26.el9fdp | Fixed | RHSA-2025:1094 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn23.09-0:23.09.6-12.el9fdp | Fixed | RHSA-2025:1095 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn24.03-0:24.03.4-53.el9fdp | Fixed | RHSA-2025:1096 |
| Fast Datapath for Red Hat Enterprise Linux 9 | ovn24.09-0:24.09.1-66.el9fdp | Fixed | RHSA-2025:1097 |
| Red Hat OpenShift Container Platform 4 | ovn22.06 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | ovn22.09 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | ovn22.12 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | ovn23.03 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | ovn23.06 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | ovn23.09 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | ovn24.03 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | ovn24.09 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Red Hat Product Security has not identified any mitigations at this time. We recommend updating to a known patched version of OVN.
Red Hat statement
Fixes for OpenShift Container Platform ovn component will be consumed from RHEL Fast Datapath.
Red Hat mitigation
Red Hat Product Security has not identified any mitigations at this time. We recommend updating to a known patched version of OVN.
References (22)
- http://www.openwall.com/lists/oss-security/2025/01/22/11
- https://access.redhat.com/errata/RHSA-2025:1083 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1084 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1085 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1086 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1087 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1088 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1089 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1090 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1091 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1092 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1093 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1094 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1095 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1096 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1097 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-0650 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2339537 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1804 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-0650
- https://www.cve.org/CVERecord?id=CVE-2025-0650
- https://www.openwall.com/lists/oss-security/2025/01/22/5
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data