CVE Vulnerabilities

CVE-2024-2182

Origin Validation Error

Published: Mar 12, 2024 | Modified: Sep 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Fast Datapath for Red Hat Enterprise Linux 8 RedHat ovn23.06-0:23.06.1-112.el8fdp *
Fast Datapath for Red Hat Enterprise Linux 8 RedHat ovn22.12-0:22.12.1-94.el8fdp *
Fast Datapath for Red Hat Enterprise Linux 8 RedHat ovn22.03-0:22.03.3-71.el8fdp *
Fast Datapath for Red Hat Enterprise Linux 8 RedHat ovn23.03-0:23.03.1-100.el8fdp *
Fast Datapath for Red Hat Enterprise Linux 8 RedHat ovn-2021-0:21.12.0-142.el8fdp *
Fast Datapath for Red Hat Enterprise Linux 9 RedHat ovn23.09-0:23.09.0-136.el9fdp *
Fast Datapath for Red Hat Enterprise Linux 9 RedHat ovn23.06-0:23.06.1-112.el9fdp *
Fast Datapath for Red Hat Enterprise Linux 9 RedHat ovn22.12-0:22.12.1-94.el9fdp *
Fast Datapath for Red Hat Enterprise Linux 9 RedHat ovn22.03-0:22.03.3-71.el9fdp *
Fast Datapath for Red Hat Enterprise Linux 9 RedHat ovn23.03-0:23.03.1-100.el9fdp *
Ovn Ubuntu focal *
Ovn Ubuntu jammy *
Ovn Ubuntu mantic *
Ovn Ubuntu upstream *

References