CVE-2024-2182

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
Configurations

No configuration.

History

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/12/5 -

23 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/ -

22 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/ -

22 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/ -

19 Mar 2024, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1385 -
  • () https://access.redhat.com/errata/RHSA-2024:1386 -
  • () https://access.redhat.com/errata/RHSA-2024:1387 -
  • () https://access.redhat.com/errata/RHSA-2024:1388 -
  • () https://access.redhat.com/errata/RHSA-2024:1390 -
  • () https://access.redhat.com/errata/RHSA-2024:1391 -
  • () https://access.redhat.com/errata/RHSA-2024:1392 -
  • () https://access.redhat.com/errata/RHSA-2024:1393 -
  • () https://access.redhat.com/errata/RHSA-2024:1394 -
Summary
  • (es) Se encontró una falla en la Red Virtual Abierta (OVN). En los clústeres OVN donde se utiliza BFD entre hipervisores para alta disponibilidad, un atacante puede inyectar paquetes BFD especialmente manipulados desde cargas de trabajo sin privilegios, incluidas máquinas virtuales o contenedores, que pueden desencadenar una denegación de servicio.

12 Mar 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 17:15

Updated : 2024-05-01 18:15


NVD link : CVE-2024-2182

Mitre link : CVE-2024-2182

CVE.ORG link : CVE-2024-2182


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error