PT-2022-6526 · Mirantis+7 · Mirantis Container Runtime+7

Corhere

·

Published

2022-03-15

·

Updated

2025-10-11

·

CVE-2023-28840

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Moby versions prior to 23.0.3 Moby versions prior to 20.10.24 Mirantis Container Runtime versions prior to 20.10.16
Description The issue is related to the use of an unsecured alternative channel in the Swarm Mode of the Moby daemon component. This can enable a Denial of Service attack and potentially allow a sophisticated attacker to establish a UDP or TCP connection by way of the container’s outbound gateway that would otherwise be blocked by a stateful firewall. The vulnerability is due to the injection of arbitrary Ethernet frames, which can be used to smuggle packets into the overlay network. Encrypted overlay networks function by encapsulating the VXLAN datagrams through the use of the IPsec Encapsulating Security Payload protocol in Transport mode. However, the rules set by Moby to discard unencrypted VXLAN datagrams can be overridden by administrator-set rules, potentially admitting unencrypted datagrams that should have been discarded.
Recommendations Update to Moby release 23.0.3 or later. Update to Moby release 20.10.24 or later. Update to Mirantis Container Runtime release 20.10.16 or later. As a temporary workaround, consider closing the VXLAN port (by default, UDP port 4789) to incoming traffic at the Internet boundary to prevent all VXLAN packet injection. Ensure that the xt u32 kernel module is available on all nodes of the Swarm cluster.

Exploit

Fix

DoS

Improper Handling of Exceptional Conditions

Side Channel Attack

Missing Encryption of Sensitive Data

Related Identifiers

BDU:2023-02005
CVE-2023-28840
GHSA-232P-VWFF-86MP
GHSA-33PG-M6JH-5237
GHSA-6WRF-MXFJ-PF5P
GHSA-GVM4-2QQG-M333
GHSA-VWM3-CRMR-XFXW
GO-2023-1699
GO-2023-1700
GO-2023-1701
MGASA-2023-0329
OESA-2023-1238
OPENSUSE-SU-2023_3536-1
OPENSUSE-SU-2024:12876-1
OPENSUSE-SU-2024:13005-1
OPENSUSE-SU-2024:13205-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2023:3307-1
SUSE-SU-2023:3536-1
SUSE-SU-2023_3307-1
SUSE-SU-2023_3536-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1
USN-7474-1

Affected Products

Astra Linux
Debian
Docker
Linuxmint
Mirantis Container Runtime
Red Os
Suse
Ubuntu