Unprotected Alternate Channel in moby - CVE-2023-28840

 

Unprotected Alternate Channel in moby - CVE-2023-28840

Published: April 5, 2023


Vulnerability identifier: #VU74468
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28840
CWE-ID: CWE-420
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to unprotected alternate channel within encrypted overlay networks. A remote attacker can inject arbitrary Ethernet frames into the encrypted overlay network and perform a denial of service (DoS) attack.


Affected software

moby
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Fedora
ObjectScale
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
IBM Cloud Pak for Multicloud Management
Dell EMC Container Storage Modules
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
docker-engine
docker-debuginfo
docker
docker-fish-completion
docker-zsh-completion
docker-bash-completion
moby-engine
app-containers/docker
IBM Cloud Pak System
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Business Automation
Dell EMC VxRail Appliance

How to mitigate CVE-2023-28840

Install updates from vendor's website.

moby - addressed in versions 20.10.24, 23.0.3
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
docker.io (Ubuntu package) - update to Ubuntu Pro
golang-github-docker-docker-dev (Ubuntu package) - update to Ubuntu Pro
Dell EMC Container Storage Modules - update to 1.7.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.7
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC VxRail Appliance - update to 8.0.120
docker-engine - update to 18.09.0-253
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
docker-debuginfo - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
docker - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
docker-fish-completion - update to 24.0.5_ce-150000.185.1
docker-zsh-completion - update to 24.0.5_ce-150000.185.1
docker-bash-completion - update to 24.0.5_ce-150000.185.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
app-containers/docker - update to 25.0.4

External References

Related Security Bulletins