CVE-2023-1668
openvswitch: ip proto 0 triggers incorrect handling
Severity Score
8.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-03-27 CVE Reserved
- 2023-04-10 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-670: Always-Incorrect Control Flow Implementation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/05/msg00000.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.openwall.com/lists/oss-security/2023/04/06/1 | 2023-11-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Fast Datapath Search vendor "Redhat" for product "Fast Datapath" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Safe
|
Redhat Search vendor "Redhat" | Fast Datapath Search vendor "Redhat" for product "Fast Datapath" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Safe
|
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 1.5.0 < 2.13.11 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 1.5.0 < 2.13.11" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 2.14.0 < 2.14.9 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 2.14.0 < 2.14.9" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 2.15.0 < 2.15.8 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 2.15.0 < 2.15.8" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 2.16.0 < 2.16.7 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 2.16.0 < 2.16.7" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 2.17.0 < 2.17.6 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 2.17.0 < 2.17.6" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | >= 3.0.0 < 3.0.4 Search vendor "Cloudbase" for product "Open Vswitch" and version " >= 3.0.0 < 3.0.4" | - |
Affected
| ||||||
Cloudbase Search vendor "Cloudbase" | Open Vswitch Search vendor "Cloudbase" for product "Open Vswitch" | 3.1.0 Search vendor "Cloudbase" for product "Open Vswitch" and version "3.1.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.0 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Platform Search vendor "Redhat" for product "Openstack Platform" | 16.1 Search vendor "Redhat" for product "Openstack Platform" and version "16.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Platform Search vendor "Redhat" for product "Openstack Platform" | 16.2 Search vendor "Redhat" for product "Openstack Platform" and version "16.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Platform Search vendor "Redhat" for product "Openstack Platform" | 17.0 Search vendor "Redhat" for product "Openstack Platform" and version "17.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Virtualization Search vendor "Redhat" for product "Virtualization" | 4.0 Search vendor "Redhat" for product "Virtualization" and version "4.0" | - |
Affected
|