CVE-2023-3966
published 2024-02-22CVE-2023-3966: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.03%
60.0th percentile
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 3.1.0-2+deb12u1 (bookworm) | openvswitch 3.1.0-2+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_openvswitch_2.17.5-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_openvswitch_3.3.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_openvswitch_2.17.9-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openvswitch | openvswitch | < 3.1.0 | 3.1.0 |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-2+deb11u5 | 2.15.0+ds1-2+deb11u5 |
| openvswitch | openvswitch | >= 0 < 3.1.0-2+deb12u1 | 3.1.0-2+deb12u1 |
| openvswitch | openvswitch | >= 0 < 3.3.0-1 | 3.3.0-1 |
| openvswitch | openvswitch | >= 0 < 3.3.0-1 | 3.3.0-1 |
| openvswitch | openvswitch | >= 0 < 2.13.8-0ubuntu1.4 | 2.13.8-0ubuntu1.4 |
| openvswitch | openvswitch | >= 0 < 2.17.9-0ubuntu0.22.04.1 | 2.17.9-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2024-03-12·CVSS 7.5
CVE-2023-5366 [HIGH] Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
Timothy Redaelli and Haresh Khandelwal discovered that Open vSwitch
incorrectly handled certain crafted Geneve packets when hardware offloading
via the netlink path is enabled. A remote attacker could possibly use this
issue to cause Open vSwitch to crash, leading to a denial of service.
(CVE-2023-3966)
It was discovered that Open vSwitch incorrectly handled certain ICMPv6
Neighbor Advertisement packets. A remote attacker could possibly use this
issue to redirect traffic to arbitrary IP addresses. (CVE-2023-5366)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Microsoft
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2023-3966 [HIGH] CWE-248 Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releas
Red Hat
openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
vendor_redhat·2024-02-08·CVSS 7.5
CVE-2023-3966 [HIGH] CWE-248 openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
Package: openvswitch (Fast Datapath for RHEL 7) - Out of support scope
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Out of support scope
Package: openvswitch2.11 (Fast Datapath for RHEL 7) -
Debian
CVE-2023-3966: openvswitch - A flaw was found in Open vSwitch where multiple versions are vulnerable to craft...
vendor_debian·2023·CVSS 7.5
CVE-2023-3966 [HIGH] CVE-2023-3966: openvswitch - A flaw was found in Open vSwitch where multiple versions are vulnerable to craft...
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
Scope: local
bookworm: resolved (fixed in 3.1.0-2+deb12u1)
bullseye: resolved (fixed in 2.15.0+ds1-2+deb11u5)
forky: resolved (fixed in 3.3.0-1)
sid: resolved (fixed in 3.3.0-1)
trixie: resolved (fixed in 3.3.0-1)
OSV
openvswitch vulnerabilities
osv·2024-03-12·CVSS 7.5
CVE-2023-3966 [HIGH] openvswitch vulnerabilities
openvswitch vulnerabilities
Timothy Redaelli and Haresh Khandelwal discovered that Open vSwitch
incorrectly handled certain crafted Geneve packets when hardware offloading
via the netlink path is enabled. A remote attacker could possibly use this
issue to cause Open vSwitch to crash, leading to a denial of service.
(CVE-2023-3966)
It was discovered that Open vSwitch incorrectly handled certain ICMPv6
Neighbor Advertisement packets. A remote attacker could possibly use this
issue to redirect traffic to arbitrary IP addresses. (CVE-2023-5366)
OSV
CVE-2023-3966: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid
osv·2024-02-22·CVSS 7.5
CVE-2023-3966 [HIGH] CVE-2023-3966: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
GHSA
GHSA-r9cj-pfgj-jc26: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid
ghsa_unreviewed·2024-02-22
CVE-2023-3966 [HIGH] CWE-248 GHSA-r9cj-pfgj-jc26: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-3966 openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
bugzilla·2023-03-15·CVSS 7.5
CVE-2023-3966 [HIGH] CVE-2023-3966 openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
CVE-2023-3966 openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
ovs-vswitch fails to recover after malformed geneve metadata packet
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 2264263]
---
This issue has been addressed in the following products:
Fast Datapath for Red Hat Enterprise Linux 8
Via RHSA-2024:1234 https://access.redhat.com/errata/RHSA-2024:1234
---
This issue has been addressed in the following products:
Fast Datapath for Red Hat Enterprise Linux 8
Via RHSA-2024:1235 https://access.redhat.com/errata/RHSA-2024:1235
---
This issue has been addressed in the following products:
Fast Datapath for Red Hat Enterprise Linux 9
Via RHSA-2024:1227 https://access.redhat.com/errata/RHSA-2024:1227
Bleepingcomputer
Hackers use Citrix Bleed flaw in attacks on govt networks worldwide
blogs_bleepingcomputer·2023-11-01·CVSS 7.5
CVE-2023-4966 [HIGH] Hackers use Citrix Bleed flaw in attacks on govt networks worldwide
## Hackers use Citrix Bleed flaw in attacks on govt networks worldwide
## Bill Toulas
Threat actors are leveraging the 'Citrix Bleed' vulnerability, tracked as CVE-2023-4966, to target government, technical, and legal organizations in the Americas, Europe, Africa, and the Asia-Pacific region.
Researchers from Mandiant report that four ongoing campaigns target vulnerable Citrix NetScaler ADC and Gateway appliances, with attacks underway since late August 2023.
The security company has seen post-exploitation activity related to credential theft and lateral movement, warning that exploitation leaves behind limited forensic evidence, making these attacks particularly stealthy.
## Citrix Bleed
The Citrix Bleed CVE-2023-4966 vulnerability was disclosed on October 10 as a critical severity
https://access.redhat.com/security/cve/CVE-2023-3966https://bugzilla.redhat.com/show_bug.cgi?id=2178363https://lists.fedoraproject.org/archives/list/[email protected]/message/LFZADABUDOFI2KZIRQBYFZCIKH55RGY3/https://lists.fedoraproject.org/archives/list/[email protected]/message/VYYUBF6OW2JG7VOFEOROHXGSJCTES3QO/https://access.redhat.com/security/cve/CVE-2023-3966https://bugzilla.redhat.com/show_bug.cgi?id=2178363https://lists.fedoraproject.org/archives/list/[email protected]/message/LFZADABUDOFI2KZIRQBYFZCIKH55RGY3/https://lists.fedoraproject.org/archives/list/[email protected]/message/VYYUBF6OW2JG7VOFEOROHXGSJCTES3QO/
2024-02-22
Published