Back

HIGH

Ovn: egress acls may be bypassed via specially crafted udp packet

Published Jan 23, 2025

Description

A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.

Affected products

Remediation

Vendor solution

Red Hat Product Security has not identified any mitigations at this time. We recommend updating to a known patched version of OVN.

Red Hat statement

Fixes for OpenShift Container Platform ovn component will be consumed from RHEL Fast Datapath.

Red Hat mitigation

Red Hat Product Security has not identified any mitigations at this time. We recommend updating to a known patched version of OVN.

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jan 23, 2025
Updated Nov 20, 2025
Reserved Jan 22, 2025

CISA Vulnrichment

Updated Jan 23, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Jan 21, 2024
Bugzilla 2339537

ENISA EUVD

Assigner redhat
Published Jan 23, 2025
Updated Nov 20, 2025

GitHub

No data