NA

CVE-2023-3966

Published: 22/02/2024 Updated: 23/03/2024

Vulnerability Summary

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1063492 openvswitch: CVE-2023-3966: Invalid memory access in Geneve with HW offload Package: src:openvswitch; Maintainer for src:openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 8 Feb 2024 21:39:04 UTC Seve ...

Mailing Lists

Description =========== Multiple versions of Open vSwitch are vulnerable to crafted Geneve packets causing invalid memory accesses and potential denial of service Triggering the vulnerability requires that Open vSwitch has flow hardware offload with Linux TC flower enabled (other_config:hw-offload=true) It is not enabled by default The issue i ...