CVE-2023-5366
Openvswitch don't match packets on nd_target field
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Produtos afetados
Fedora · Fedoran/a · openvswitchRed Hat · Fast Datapath for RHEL 7Red Hat · Fast Datapath for RHEL 8Red Hat · Fast Datapath for RHEL 9Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat OpenShift Container Platform 3.11Red Hat · Red Hat OpenShift Container Platform 4Red Hat · Red Hat OpenStack Platform 16.1Red Hat · Red Hat OpenStack Platform 16.2Red Hat · Red Hat Virtualization 4Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/security/cve/CVE-2023-5366https://bugzilla.redhat.com/show_bug.cgi?id=2006347https://lists.debian.org/debian-lts-announce/2024/02/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LFZADABUDOFI2KZIRQBYFZCIKH55RGY3/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VYYUBF6OW2JG7VOFEOROHXGSJCTES3QO/http://www.openwall.com/lists/oss-security/2024/02/08/4