CVE Vulnerabilities

CVE-2024-2182

Origin Validation Error

Published: Mar 12, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Fast Datapath for Red Hat Enterprise Linux 8RedHatovn23.06-0:23.06.1-112.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatovn22.12-0:22.12.1-94.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatovn22.03-0:22.03.3-71.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatovn23.03-0:23.03.1-100.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatovn-2021-0:21.12.0-142.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatovn23.09-0:23.09.0-136.el9fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatovn23.06-0:23.06.1-112.el9fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatovn22.12-0:22.12.1-94.el9fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatovn22.03-0:22.03.3-71.el9fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatovn23.03-0:23.03.1-100.el9fdp*
OvnUbuntuesm-infra/focal*
OvnUbuntufocal*
OvnUbuntujammy*
OvnUbuntumantic*
OvnUbuntuupstream*

References