Out-of-bounds read in Open vSwitch - CVE-2023-3966

 

Out-of-bounds read in Open vSwitch - CVE-2023-3966

Published: February 9, 2024 / Updated: February 9, 2024


Vulnerability identifier: #VU86295
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3966
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when handling Geneve packets. A remote attacker can send specially crafted Geneve packets with HF offload to the system, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

Open vSwitch
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Red Hat Enterprise Linux Fast Datapath
openvswitch
openvswitch-devel
python3-openvswitch
openvswitch-debugsource
openvswitch-help
openvswitch-debuginfo
openvswitch-common (Ubuntu package)
python3-openvswitch (Ubuntu package)
openvswitch (Debian package)
openvswitch-test
network-scripts-openvswitch
openvswitch-ipsec
openvswitch-testcontroller
openvswitch-doc
openvswitch3.1 (Red Hat package)
openvswitch3-pki
openvswitch3-doc
openvswitch3
openvswitch3-test
openvswitch3-debuginfo
python3-ovs3
openvswitch3-ipsec
openvswitch3-devel
libopenvswitch-3_1-0
libopenvswitch-3_1-0-debuginfo
openvswitch3-vtep
openvswitch3-test-debuginfo
openvswitch3-vtep-debuginfo
openvswitch3-debugsource
ovn3-central
ovn3
ovn3-host
ovn3-host-debuginfo
ovn3-docker
ovn3-central-debuginfo
libovn-23_03-0-debuginfo
ovn3-debuginfo
ovn3-vtep-debuginfo
libovn-23_03-0
ovn3-devel
ovn3-vtep
ovn3-doc
Red Hat OpenShift Container Platform

How to mitigate CVE-2023-3966

Install updates from vendor's website.

Open vSwitch - addressed in versions 2.17.9, 3.0.6, 3.1.4, 3.2.2
openvswitch - update to 2.12.4-8
openvswitch-devel - update to 2.12.4-8
python3-openvswitch - update to 2.12.4-8
openvswitch-debugsource - update to 2.12.4-8
openvswitch-help - update to 2.12.4-8
openvswitch-debuginfo - update to 2.12.4-8
openvswitch-common (Ubuntu package) - addressed in versions 2.13.8-0ubuntu1.4, 2.17.9-0ubuntu0.22.04.1, 3.2.2-0ubuntu0.23.10.1
python3-openvswitch (Ubuntu package) - addressed in versions 2.13.8-0ubuntu1.4, 2.17.9-0ubuntu0.22.04.1, 3.2.2-0ubuntu0.23.10.1
openvswitch (Debian package) - addressed in versions 2.15.0+ds1-2+deb11u5, 3.1.0-2+deb12u1
openvswitch-test - update to 2.17.6-3
network-scripts-openvswitch - update to 2.17.6-3
openvswitch - update to 2.17.6-3
openvswitch-devel - update to 2.17.6-3
openvswitch-ipsec - update to 2.17.6-3
openvswitch-testcontroller - update to 2.17.6-3
python3-openvswitch - update to 2.17.6-3
openvswitch-doc - update to 2.17.6-3
openvswitch3.1 (Red Hat package) - addressed in versions 3.1.0-88.el9fdp, 3.1.0-96.el8fdp
openvswitch3-pki - update to 3.1.0-150500.3.16.1
openvswitch3-doc - update to 3.1.0-150500.3.16.1
openvswitch3 - update to 3.1.0-150500.3.16.1
openvswitch3-test - update to 3.1.0-150500.3.16.1
openvswitch3-debuginfo - update to 3.1.0-150500.3.16.1
python3-ovs3 - update to 3.1.0-150500.3.16.1
openvswitch3-ipsec - update to 3.1.0-150500.3.16.1
openvswitch3-devel - update to 3.1.0-150500.3.16.1
libopenvswitch-3_1-0 - update to 3.1.0-150500.3.16.1
libopenvswitch-3_1-0-debuginfo - update to 3.1.0-150500.3.16.1
openvswitch3-vtep - update to 3.1.0-150500.3.16.1
openvswitch3-test-debuginfo - update to 3.1.0-150500.3.16.1
openvswitch3-vtep-debuginfo - update to 3.1.0-150500.3.16.1
openvswitch3-debugsource - update to 3.1.0-150500.3.16.1
openvswitch - addressed in versions 3.2.2-1.fc39, 3.3.0-1.fc40
Red Hat OpenShift Container Platform - addressed in versions 4.12.58, 4.14.26, 4.15.14
ovn3-central - update to 23.03.0-150500.3.16.1
ovn3 - update to 23.03.0-150500.3.16.1
ovn3-host - update to 23.03.0-150500.3.16.1
ovn3-host-debuginfo - update to 23.03.0-150500.3.16.1
ovn3-docker - update to 23.03.0-150500.3.16.1
ovn3-central-debuginfo - update to 23.03.0-150500.3.16.1
libovn-23_03-0-debuginfo - update to 23.03.0-150500.3.16.1
ovn3-debuginfo - update to 23.03.0-150500.3.16.1
ovn3-vtep-debuginfo - update to 23.03.0-150500.3.16.1
libovn-23_03-0 - update to 23.03.0-150500.3.16.1
ovn3-devel - update to 23.03.0-150500.3.16.1
ovn3-vtep - update to 23.03.0-150500.3.16.1
ovn3-doc - update to 23.03.0-150500.3.16.1

External References

Related Security Bulletins