Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3966

Опубликовано: 08 фев. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchOut of support scope
Fast Datapath for RHEL 7openvswitch2.10Out of support scope
Fast Datapath for RHEL 7openvswitch2.11Out of support scope
Fast Datapath for RHEL 7openvswitch2.12Out of support scope
Fast Datapath for RHEL 7openvswitch2.13Out of support scope
Fast Datapath for RHEL 8openvswitch2.11Out of support scope
Fast Datapath for RHEL 8openvswitch2.12Out of support scope
Fast Datapath for RHEL 8openvswitch2.13Out of support scope
Fast Datapath for RHEL 8openvswitch2.15Out of support scope
Fast Datapath for RHEL 8openvswitch2.16Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2178363openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

CVSS3: 7.5
nvd
около 2 лет назад

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

CVSS3: 7.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 2 лет назад

A flaw was found in Open vSwitch where multiple versions are vulnerabl ...

suse-cvrf
около 2 лет назад

Security update for openvswitch

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3