PT-2023-9382 · Unknown+5 · Openvswitch+5

David Marchand

·

Published

2023-04-03

·

Updated

2026-01-26

·

CVE-2023-1668

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions openvswitch (affected versions not specified)
Description A flaw was found in openvswitch (OVS) when processing an IP packet with protocol 0. This issue results in installing a datapath flow matching all IP protocols for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow. The vulnerability may allow a remote attacker to access confidential data and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1745
ALT-PU-2023-1806
AZL-26031
AZL-35088
BDU:2024-06943
CVE-2023-1668
DLA-3410-1
DSA-5387-1
OESA-2023-1234
OPENSUSE-SU-2024:12942-1
RHSA-2023:1765
RHSA-2023:1766
RHSA-2023:1769
RHSA-2023:1770
RHSA-2023:1823
RHSA-2023:1824
RHSA-2023:3491
SUSE-SU-2023:2274-1
SUSE-SU-2023:2275-1
SUSE-SU-2023:2296-1
SUSE-SU-2023:2536-1
SUSE-SU-2023:2621-1
SUSE-SU-2023_2296-1
SUSE-SU-2023_2536-1
SUSE-SU-2023_2621-1
SUSE-SU-2026:0280-1
SUSE-SU-2026:0290-1
USN-6068-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Openvswitch