CVE-2024-2182

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
References
Link Resource
https://access.redhat.com/errata/RHSA-2024:1385
https://access.redhat.com/errata/RHSA-2024:1386
https://access.redhat.com/errata/RHSA-2024:1387
https://access.redhat.com/errata/RHSA-2024:1388
https://access.redhat.com/errata/RHSA-2024:1390
https://access.redhat.com/errata/RHSA-2024:1391
https://access.redhat.com/errata/RHSA-2024:1392
https://access.redhat.com/errata/RHSA-2024:1393
https://access.redhat.com/errata/RHSA-2024:1394
https://access.redhat.com/errata/RHSA-2024:4035
https://access.redhat.com/security/cve/CVE-2024-2182
https://bugzilla.redhat.com/show_bug.cgi?id=2267840
https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
https://www.openwall.com/lists/oss-security/2024/03/12/5
http://www.openwall.com/lists/oss-security/2024/03/12/5
https://access.redhat.com/errata/RHSA-2024:1385
https://access.redhat.com/errata/RHSA-2024:1386
https://access.redhat.com/errata/RHSA-2024:1387
https://access.redhat.com/errata/RHSA-2024:1388
https://access.redhat.com/errata/RHSA-2024:1390
https://access.redhat.com/errata/RHSA-2024:1391
https://access.redhat.com/errata/RHSA-2024:1392
https://access.redhat.com/errata/RHSA-2024:1393
https://access.redhat.com/errata/RHSA-2024:1394
https://access.redhat.com/errata/RHSA-2024:4035
https://access.redhat.com/security/cve/CVE-2024-2182
https://bugzilla.redhat.com/show_bug.cgi?id=2267840
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/
https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
https://www.openwall.com/lists/oss-security/2024/03/12/5
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-12 17:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2182

Mitre link : CVE-2024-2182

CVE.ORG link : CVE-2024-2182


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error