CVE-2023-1668
published 2023-04-10CVE-2023-1668: A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP…
PriorityP343high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
1.22%
65.2th percentile
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cloudbase | open_vswitch | — | — |
| cloudbase | open_vswitch | >= 1.5.0 < 2.13.11 | 2.13.11 |
| cloudbase | open_vswitch | >= 2.14.0 < 2.14.9 | 2.14.9 |
| cloudbase | open_vswitch | >= 2.15.0 < 2.15.8 | 2.15.8 |
| cloudbase | open_vswitch | >= 2.16.0 < 2.16.7 | 2.16.7 |
| cloudbase | open_vswitch | >= 2.17.0 < 2.17.6 | 2.17.6 |
| cloudbase | open_vswitch | >= 3.0.0 < 3.0.4 | 3.0.4 |
| debian | debian_linux | — | — |
| debian | openvswitch | < openvswitch 3.1.0-2 (bookworm) | openvswitch 3.1.0-2 (bookworm) |
| msrc | azl3_openvswitch_2.17.5-3_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_openvswitch_2.17.5-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-2+deb11u4 | 2.15.0+ds1-2+deb11u4 |
| openvswitch | openvswitch | >= 0 < 3.1.0-2 | 3.1.0-2 |
| openvswitch | openvswitch | >= 0 < 3.1.0-2 | 3.1.0-2 |
| openvswitch | openvswitch | >= 0 < 3.1.0-2 | 3.1.0-2 |
| redhat | openshift_container_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open vSwitch vulnerability
vendor_ubuntu·2023-05-10
CVE-2023-1668 Open vSwitch vulnerability
Title: Open vSwitch vulnerability
Summary: Open vSwitch could be made to stop forwarding packets if it received
specially crafted network traffic.
David Marchand discovered that Open vSwitch incorrectly handled IP packets
with the protocol set to 0. A remote attacker could possibly use this issue
to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0 OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel a
vendor_msrc·2023-04-11·CVSS 8.2
CVE-2023-1668 [HIGH] CWE-670 A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0 OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel a
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0 OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow but with an incorrect action possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
Red Hat
openvswitch: ip proto 0 triggers incorrect handling
vendor_redhat·2023-04-06·CVSS 8.2
CVE-2023-1668 [HIGH] CWE-670 openvswitch: ip proto 0 triggers incorrect handling
openvswitch: ip proto 0 triggers incorrect handling
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto
Debian
CVE-2023-1668: openvswitch - A flaw was found in openvswitch (OVS). When processing an IP packet with protoco...
vendor_debian·2023·CVSS 8.2
CVE-2023-1668 [HIGH] CVE-2023-1668: openvswitch - A flaw was found in openvswitch (OVS). When processing an IP packet with protoco...
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
Scope: local
bookworm: resolved (fixed in 3.1.0-2)
bullseye: resolved (fixed in 2.15.0+ds1-2+deb11u4)
forky: resolved (fixed in 3.1.0-2)
sid: resolved (fixed in 3.1.0-2)
trixie: resolved (fixed in 3.1.0-2)
GHSA
Denial of Service issue in quinn-proto
ghsa·2023-09-21
CVE-2023-42805 [HIGH] CWE-20 Denial of Service issue in quinn-proto
Denial of Service issue in quinn-proto
### Impact
Receiving unknown QUIC frames in a QUIC packet could result in a panic.
### Patches
The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases.
### References
Fixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669.
GHSA
GHSA-w6wj-g5cv-fh4w: A flaw was found in openvswitch (OVS)
ghsa_unreviewed·2023-04-11
CVE-2023-1668 [HIGH] CWE-670 GHSA-w6wj-g5cv-fh4w: A flaw was found in openvswitch (OVS)
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
OSV
CVE-2023-1668: A flaw was found in openvswitch (OVS)
osv·2023-04-10·CVSS 8.2
CVE-2023-1668 [HIGH] CVE-2023-1668: A flaw was found in openvswitch (OVS)
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2137666https://lists.debian.org/debian-lts-announce/2023/05/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2GUNS3WSJG4TUDKZ5L7FXGJMVOD6EJZ/https://security.gentoo.org/glsa/202311-16https://www.debian.org/security/2023/dsa-5387https://www.openwall.com/lists/oss-security/2023/04/06/1https://bugzilla.redhat.com/show_bug.cgi?id=2137666https://lists.debian.org/debian-lts-announce/2023/05/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2GUNS3WSJG4TUDKZ5L7FXGJMVOD6EJZ/https://security.gentoo.org/glsa/202311-16https://www.debian.org/security/2023/dsa-5387https://www.openwall.com/lists/oss-security/2023/04/06/1
2023-04-10
Published