Insufficient verification of data authenticity in Open vSwitch - CVE-2023-5366
Published: November 22, 2023 / Updated: February 9, 2024
Open vSwitch
openvswitch.org
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to missing verification of data authenticity when handling ICMPv6 Neighbor Advertisement packets between virtual machines. A local user can bypass OpenFlow rules and send otherwise restricted packets.