CVE-2024-2182 Information

Description

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability an attacker can inject specially crafted BFD packets from inside unprivileged workloads including virtual machines or containers that can trigger a denial of service.

Reference

https://access.redhat.com/security/cve/CVE-2024-2182 https://bugzilla.redhat.com/show_bug.cgi?id=2267840 https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html https://www.openwall.com/lists/oss-security/2024/03/12/5

Share on: