UBUNTU-CVE-2023-5366
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5366
UBUNTU-CVE-2023-5366
Summary:
Details: A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
References: https://ubuntu.com/security/CVE-2023-5366, https://ubuntu.com/security/notices/USN-6514-1, https://mail.openvswitch.org/pipermail/ovs-announce/2024-February/000342.html, https://ubuntu.com/security/notices/USN-6690-1, https://www.cve.org/CVERecord?id=CVE-2023-5366
Affected packages
Package
Name: openvswitch
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
