NA

CVE-2024-2182

Published: 12/03/2024 Updated: 01/05/2024

Vulnerability Summary

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [ADVISORY] CVE-2024-2182: Open Virtual Network: Insufficient validation of incoming BFD packets <!--X-Subject-Header-End--> < ...