PT-2023-8636 · Unknown+6 · Openvswitch+6

Anten Skrabec

+1

·

Published

2023-03-15

·

Updated

2026-01-26

·

CVE-2023-3966

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open vSwitch (affected versions not specified)
Description A flaw in Open vSwitch is related to insufficient handling of exceptional states due to incorrect checking of Geneve packet metadata. This issue may allow a remote attacker to cause a denial of service if hardware offloading via the netlink path is enabled. The flaw is triggered by crafted Geneve packets and may result in invalid memory accesses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10743
ALT-PU-2024-6293
AZL-35089
BDU:2024-01316
CVE-2023-3966
DSA-5640-1
OESA-2024-1207
OPENSUSE-SU-2024:13725-1
RHSA-2024:1227
RHSA-2024:1234
RHSA-2024:1235
SUSE-SU-2024:0738-1
SUSE-SU-2024:0738-2
SUSE-SU-2024:0912-1
SUSE-SU-2024:0922-1
SUSE-SU-2024:0937-1
SUSE-SU-2024_0738-1
SUSE-SU-2024_0912-1
SUSE-SU-2024_0922-1
SUSE-SU-2024_0937-1
SUSE-SU-2026:0280-1
SUSE-SU-2026:0290-1
SUSE-SU-2026:20049-1
SUSE-SU-2026:20061-1
USN-6690-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openvswitch
Red Os
Suse
Ubuntu