← Back

CVE-2023-1668

nvd nist
Published: Apr 10, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Exploitability: 3.9 / Impact: 4.2
Source: NVD

Description

A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.

Affected (14)

1 product
Open Vswitch
1 product
Debian Linux
4 products
Openshift Container Platform
Openstack Platform
Virtualization
Fast Datapath
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbase
From 1.5.0 to 2.13.11
From 2.14.0 to 2.14.9
From 2.15.0 to 2.15.8
From 2.16.0 to 2.16.7
From 2.17.0 to 2.17.6
From 3.0.0 to 3.0.4
Version 3.1.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0
Redhat
Version 16.1
Version 16.2
Version 17.0
Version 4.0
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0

References (12)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListMitigationPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationPatch

Timeline

No history available yet.