Input validation error in Open Virtual Network - CVE-2024-2182
Published: March 14, 2024
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when handling BFD packets from inside unprivileged workloads. A remote user with access to a virtual machine or a container can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
openSUSE Leap
Ubuntu
Fedora
Red Hat Enterprise Linux Fast Datapath
openvswitch-debuginfo
openvswitch-debugsource
libopenvswitch-2_11-0-debuginfo
openvswitch
libopenvswitch-2_11-0
python3-ovs
openvswitch-test
openvswitch-vtep-debuginfo
openvswitch-pki
openvswitch-doc
libopenvswitch-2_14-0-debuginfo
libopenvswitch-2_14-0
openvswitch-test-debuginfo
openvswitch-devel
openvswitch-ipsec
openvswitch-vtep
ovn-common (Ubuntu package)
ovn-host (Ubuntu package)
ovn-ic (Ubuntu package)
ovn-central (Ubuntu package)
ovn-doc
ovn-vtep-debuginfo
ovn-vtep
ovn-host
libovn-20_06-0
ovn-devel
ovn
ovn-central-debuginfo
ovn-docker
libovn-20_06-0-debuginfo
ovn-central
ovn-host-debuginfo
ovn-debuginfo
ovn-2021 (Red Hat package)
ovn22.03 (Red Hat package)
ovn22.12 (Red Hat package)
ovn23.03 (Red Hat package)
ovn23.06 (Red Hat package)
ovn23.09 (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-2182
openvswitch-debuginfo - addressed in versions 2.11.5-3.27.1, 2.14.2-150400.24.29.1
openvswitch-debugsource - addressed in versions 2.11.5-3.27.1, 2.14.2-150400.24.29.1
libopenvswitch-2_11-0-debuginfo - update to 2.11.5-3.27.1
openvswitch - addressed in versions 2.11.5-3.27.1, 2.14.2-150400.24.29.1
libopenvswitch-2_11-0 - update to 2.11.5-3.27.1
python3-ovs - update to 2.14.2-150400.24.29.1
openvswitch-test - update to 2.14.2-150400.24.29.1
openvswitch-vtep-debuginfo - update to 2.14.2-150400.24.29.1
openvswitch-pki - update to 2.14.2-150400.24.29.1
openvswitch-doc - update to 2.14.2-150400.24.29.1
libopenvswitch-2_14-0-debuginfo - update to 2.14.2-150400.24.29.1
libopenvswitch-2_14-0 - update to 2.14.2-150400.24.29.1
openvswitch-test-debuginfo - update to 2.14.2-150400.24.29.1
openvswitch-devel - update to 2.14.2-150400.24.29.1
openvswitch-ipsec - update to 2.14.2-150400.24.29.1
openvswitch-vtep - update to 2.14.2-150400.24.29.1
Red Hat OpenShift Container Platform - update to 4.12.58
ovn-common (Ubuntu package) - addressed in versions 20.03.2-0ubuntu0.20.04.5, 22.03.3-0ubuntu0.22.04.2, 23.09.0-1ubuntu0.1
ovn-host (Ubuntu package) - addressed in versions 20.03.2-0ubuntu0.20.04.5, 22.03.3-0ubuntu0.22.04.2, 23.09.0-1ubuntu0.1
ovn-ic (Ubuntu package) - addressed in versions 20.03.2-0ubuntu0.20.04.5, 22.03.3-0ubuntu0.22.04.2, 23.09.0-1ubuntu0.1
ovn-central (Ubuntu package) - addressed in versions 20.03.2-0ubuntu0.20.04.5, 22.03.3-0ubuntu0.22.04.2, 23.09.0-1ubuntu0.1
ovn-doc - update to 20.06.2-150400.24.29.1
ovn-vtep-debuginfo - update to 20.06.2-150400.24.29.1
ovn-vtep - update to 20.06.2-150400.24.29.1
ovn-host - update to 20.06.2-150400.24.29.1
libovn-20_06-0 - update to 20.06.2-150400.24.29.1
ovn-devel - update to 20.06.2-150400.24.29.1
ovn - update to 20.06.2-150400.24.29.1
ovn-central-debuginfo - update to 20.06.2-150400.24.29.1
ovn-docker - update to 20.06.2-150400.24.29.1
libovn-20_06-0-debuginfo - update to 20.06.2-150400.24.29.1
ovn-central - update to 20.06.2-150400.24.29.1
ovn-host-debuginfo - update to 20.06.2-150400.24.29.1
ovn-debuginfo - update to 20.06.2-150400.24.29.1
ovn-2021 (Red Hat package) - update to 21.12.0-142.el8fdp
ovn22.03 (Red Hat package) - update to 22.03.3-71.el9fdp
ovn22.12 (Red Hat package) - addressed in versions 22.12.1-94.el8fdp, 22.12.1-94.el9fdp
ovn23.03 (Red Hat package) - update to 23.03.1-100.el9fdp
ovn23.06 (Red Hat package) - update to 23.06.1-112.el9fdp
ovn23.09 (Red Hat package) - update to 23.09.0-136.el9fdp
ovn - addressed in versions 23.09.0-139.fc38, 23.09.0-139.fc39, 23.09.0-139.fc40
External References
Related Security Bulletins
- Denial of service in Open Virtual Network OVN
- Ubuntu update for ovn
- Fedora 40 update for ovn
- Fedora 39 update for ovn
- Fedora 38 update for ovn
- Red Hat Enterprise Linux Fast Datapath update for ovn
- Red Hat Enterprise Linux Fast Datapath 9 update for ovn
- Red Hat Enterprise Linux Fast Datapath 9 update for ovn
- Red Hat Enterprise Linux Fast Datapath 9 update for ovn
- Red Hat Enterprise Linux Fast Datapath 9 update for ovn
- Red Hat Enterprise Linux Fast Datapath 8 update for ovn
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Fast Datapath for Red Hat Enterprise Linux 8 update for ovn-2021
- SUSE update for openvswitch
- SUSE update for openvswitch