Input validation error in Open vSwitch - CVE-2023-1668
Published: April 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing IP packets. A remote attacker can send specially crafted IP packets with "ip proto" set to "0" and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that flow rules contain 'set' actions on other fields in the IP protocol header.
Affected software
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Package Hub 15
Server Applications Module
Legacy Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Fast Datapath
python-openvswitch (Ubuntu package)
python3-openvswitch (Ubuntu package)
openvswitch-common (Ubuntu package)
libopenvswitch-2_11-0-debuginfo
libopenvswitch-2_11-0
openvswitch-debuginfo
openvswitch-debugsource
openvswitch
python3-openvswitch
openvswitch-devel
openvswitch-help
openvswitch2.13 (Red Hat package)
openvswitch-test-debuginfo
openvswitch-test
python3-ovs
libopenvswitch-2_13-0
libopenvswitch-2_13-0-debuginfo
openvswitch-vtep-debuginfo
openvswitch-vtep
openvswitch-pki
openvswitch-ipsec
libopenvswitch-2_14-0
libopenvswitch-2_14-0-debuginfo
openvswitch-doc
openvswitch (Debian package)
openvswitch2.15 (Red Hat package)
openvswitch2.17 (Red Hat package)
net-misc/openvswitch
openvswitch3.1 (Red Hat package)
openvswitch3-ipsec
openvswitch3-vtep
openvswitch3
openvswitch3-debuginfo
openvswitch3-debugsource
openvswitch3-test
libopenvswitch-3_1-0-debuginfo
openvswitch3-vtep-debuginfo
openvswitch3-test-debuginfo
openvswitch3-pki
openvswitch3-devel
python3-ovs3
libopenvswitch-3_1-0
openvswitch3-doc
redhat-release-virtualization-host (Red Hat package)
ovn-central
ovn-vtep
ovn-docker
ovn-host
libovn-20_03-0
ovn
ovn-devel
libovn-20_03-0-debuginfo
ovn-vtep-debuginfo
libovn-20_06-0-debuginfo
ovn-central-debuginfo
ovn-debuginfo
ovn-host-debuginfo
libovn-20_06-0
ovn-doc
ovn3
ovn3-doc
ovn3-vtep-debuginfo
ovn3-devel
ovn3-host-debuginfo
ovn3-vtep
ovn3-host
libovn-23_03-0
ovn3-debuginfo
ovn3-docker
ovn3-central-debuginfo
libovn-23_03-0-debuginfo
ovn3-central
How to mitigate CVE-2023-1668
python-openvswitch (Ubuntu package) - update to 2.9.8-0ubuntu0.18.04.5
python3-openvswitch (Ubuntu package) - addressed in versions 2.9.8-0ubuntu0.18.04.5, 2.13.8-0ubuntu1.2, 2.17.5-0ubuntu0.22.04.2, 3.0.3-0ubuntu0.22.10.3
openvswitch-common (Ubuntu package) - addressed in versions 2.9.8-0ubuntu0.18.04.5, 2.13.8-0ubuntu1.2, 2.17.5-0ubuntu0.22.04.2, 3.0.3-0ubuntu0.22.10.3
libopenvswitch-2_11-0-debuginfo - update to 2.11.5-3.18.2
libopenvswitch-2_11-0 - update to 2.11.5-3.18.2
openvswitch-debuginfo - addressed in versions 2.11.5-3.18.2, 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-debugsource - addressed in versions 2.11.5-3.18.2, 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch - addressed in versions 2.11.5-3.18.2, 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
python3-openvswitch - update to 2.12.4-4
openvswitch - update to 2.12.4-4
openvswitch-devel - update to 2.12.4-4
openvswitch-debuginfo - update to 2.12.4-4
openvswitch-help - update to 2.12.4-4
openvswitch-debugsource - update to 2.12.4-4
openvswitch2.13 (Red Hat package) - update to 2.13.0-214.el8fdp
openvswitch-test-debuginfo - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-test - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
python3-ovs - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
libopenvswitch-2_13-0 - update to 2.13.2-150200.9.22.1
libopenvswitch-2_13-0-debuginfo - update to 2.13.2-150200.9.22.1
openvswitch-vtep-debuginfo - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-vtep - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-devel - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-pki - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-ipsec - addressed in versions 2.13.2-150200.9.22.1, 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
libopenvswitch-2_14-0 - addressed in versions 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
libopenvswitch-2_14-0-debuginfo - addressed in versions 2.14.2-150300.19.8.1, 2.14.2-150400.24.9.1
openvswitch-doc - update to 2.14.2-150400.24.9.1
openvswitch (Debian package) - update to 2.15.0+ds1-2+deb11u4
openvswitch2.15 (Red Hat package) - update to 2.15.0-136.el8fdp
openvswitch2.17 (Red Hat package) - addressed in versions 2.17.0-77.el9fdp, 2.17.0-88.el8fdp
net-misc/openvswitch - update to 2.17.6
openvswitch3.1 (Red Hat package) - addressed in versions 3.1.0-14.el9fdp, 3.1.0-17.el8fdp
openvswitch3-ipsec - update to 3.1.0-150500.3.3.1
openvswitch3-vtep - update to 3.1.0-150500.3.3.1
openvswitch3 - update to 3.1.0-150500.3.3.1
openvswitch3-debuginfo - update to 3.1.0-150500.3.3.1
openvswitch3-debugsource - update to 3.1.0-150500.3.3.1
openvswitch3-test - update to 3.1.0-150500.3.3.1
libopenvswitch-3_1-0-debuginfo - update to 3.1.0-150500.3.3.1
openvswitch3-vtep-debuginfo - update to 3.1.0-150500.3.3.1
openvswitch3-test-debuginfo - update to 3.1.0-150500.3.3.1
openvswitch3-pki - update to 3.1.0-150500.3.3.1
openvswitch3-devel - update to 3.1.0-150500.3.3.1
python3-ovs3 - update to 3.1.0-150500.3.3.1
libopenvswitch-3_1-0 - update to 3.1.0-150500.3.3.1
openvswitch3-doc - update to 3.1.0-150500.3.3.1
openvswitch - update to 3.1.1-1.fc38
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-7.el8ev
ovn-central - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-vtep - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-docker - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-host - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
libovn-20_03-0 - update to 20.03.1-150200.9.22.1
ovn - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-devel - addressed in versions 20.03.1-150200.9.22.1, 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
libovn-20_03-0-debuginfo - update to 20.03.1-150200.9.22.1
ovn-vtep-debuginfo - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
libovn-20_06-0-debuginfo - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-central-debuginfo - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-debuginfo - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-host-debuginfo - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
libovn-20_06-0 - addressed in versions 20.06.2-150300.19.8.1, 20.06.2-150400.24.9.1
ovn-doc - update to 20.06.2-150400.24.9.1
ovn3 - update to 23.03.0-150500.3.3.1
ovn3-doc - update to 23.03.0-150500.3.3.1
ovn3-vtep-debuginfo - update to 23.03.0-150500.3.3.1
ovn3-devel - update to 23.03.0-150500.3.3.1
ovn3-host-debuginfo - update to 23.03.0-150500.3.3.1
ovn3-vtep - update to 23.03.0-150500.3.3.1
ovn3-host - update to 23.03.0-150500.3.3.1
libovn-23_03-0 - update to 23.03.0-150500.3.3.1
ovn3-debuginfo - update to 23.03.0-150500.3.3.1
ovn3-docker - update to 23.03.0-150500.3.3.1
ovn3-central-debuginfo - update to 23.03.0-150500.3.3.1
libovn-23_03-0-debuginfo - update to 23.03.0-150500.3.3.1
ovn3-central - update to 23.03.0-150500.3.3.1
External References
Related Security Bulletins
- Denial of service in Open vSwitch
- Debian update for openvswitch
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.17
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch3.1
- Red Hat Enterprise Linux Fast Datapath 9 update for openvswitch2.17
- Red Hat Enterprise Linux Fast Datapath 9 update for openvswitch3.1
- Fast Datapath for Red Hat Enterprise Linux 8 update for openvswitch2.15
- Fast Datapath for Red Hat Enterprise Linux 8 update for openvswitch2.13
- Ubuntu update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 update for redhat-release-virtualization-host and redhat-virtualization-host
- SUSE update for openvswitch3
- SUSE update for openvswitch
- Fedora 38 update for openvswitch
- Gentoo update for Open vSwitch
- openEuler update for openvswitch