CVE-2024-2182

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
References
Link Resource
https://access.redhat.com/errata/RHSA-2024:1385
https://access.redhat.com/errata/RHSA-2024:1386
https://access.redhat.com/errata/RHSA-2024:1387
https://access.redhat.com/errata/RHSA-2024:1388
https://access.redhat.com/errata/RHSA-2024:1390
https://access.redhat.com/errata/RHSA-2024:1391
https://access.redhat.com/errata/RHSA-2024:1392
https://access.redhat.com/errata/RHSA-2024:1393
https://access.redhat.com/errata/RHSA-2024:1394
https://access.redhat.com/errata/RHSA-2024:4035
https://access.redhat.com/security/cve/CVE-2024-2182
https://bugzilla.redhat.com/show_bug.cgi?id=2267840
https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
https://www.openwall.com/lists/oss-security/2024/03/12/5
http://www.openwall.com/lists/oss-security/2024/03/12/5
https://access.redhat.com/errata/RHSA-2024:1385
https://access.redhat.com/errata/RHSA-2024:1386
https://access.redhat.com/errata/RHSA-2024:1387
https://access.redhat.com/errata/RHSA-2024:1388
https://access.redhat.com/errata/RHSA-2024:1390
https://access.redhat.com/errata/RHSA-2024:1391
https://access.redhat.com/errata/RHSA-2024:1392
https://access.redhat.com/errata/RHSA-2024:1393
https://access.redhat.com/errata/RHSA-2024:1394
https://access.redhat.com/errata/RHSA-2024:4035
https://access.redhat.com/security/cve/CVE-2024-2182
https://bugzilla.redhat.com/show_bug.cgi?id=2267840
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/
https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
https://www.openwall.com/lists/oss-security/2024/03/12/5
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/12/5 -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/ -
References () https://access.redhat.com/errata/RHSA-2024:1385 - () https://access.redhat.com/errata/RHSA-2024:1385 -
References () https://access.redhat.com/errata/RHSA-2024:1386 - () https://access.redhat.com/errata/RHSA-2024:1386 -
References () https://access.redhat.com/errata/RHSA-2024:1387 - () https://access.redhat.com/errata/RHSA-2024:1387 -
References () https://access.redhat.com/errata/RHSA-2024:1388 - () https://access.redhat.com/errata/RHSA-2024:1388 -
References () https://access.redhat.com/errata/RHSA-2024:1390 - () https://access.redhat.com/errata/RHSA-2024:1390 -
References () https://access.redhat.com/errata/RHSA-2024:1391 - () https://access.redhat.com/errata/RHSA-2024:1391 -
References () https://access.redhat.com/errata/RHSA-2024:1392 - () https://access.redhat.com/errata/RHSA-2024:1392 -
References () https://access.redhat.com/errata/RHSA-2024:1393 - () https://access.redhat.com/errata/RHSA-2024:1393 -
References () https://access.redhat.com/errata/RHSA-2024:1394 - () https://access.redhat.com/errata/RHSA-2024:1394 -
References () https://access.redhat.com/errata/RHSA-2024:4035 - () https://access.redhat.com/errata/RHSA-2024:4035 -
References () https://access.redhat.com/security/cve/CVE-2024-2182 - () https://access.redhat.com/security/cve/CVE-2024-2182 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2267840 - () https://bugzilla.redhat.com/show_bug.cgi?id=2267840 -
References () https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html - () https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html -
References () https://www.openwall.com/lists/oss-security/2024/03/12/5 - () https://www.openwall.com/lists/oss-security/2024/03/12/5 -

14 Sep 2024, 00:15

Type Values Removed Values Added
References
  • {'url': 'http://www.openwall.com/lists/oss-security/2024/03/12/5', 'source': 'secalert@redhat.com'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/', 'source': 'secalert@redhat.com'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/', 'source': 'secalert@redhat.com'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/', 'source': 'secalert@redhat.com'}

20 Jun 2024, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4035 -

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/12/5 -

23 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CB4N522FCS4XWAPUKRWZF6QZ657FCIDF/ -

22 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRKXOOOKD56TY3JQVB45N3GCTX3EG4BV/ -

22 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APR4GCVCMQD3DQUKXDNGIXCCYGE5V7IT/ -

19 Mar 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en la Red Virtual Abierta (OVN). En los clústeres OVN donde se utiliza BFD entre hipervisores para alta disponibilidad, un atacante puede inyectar paquetes BFD especialmente manipulados desde cargas de trabajo sin privilegios, incluidas máquinas virtuales o contenedores, que pueden desencadenar una denegación de servicio.
References
  • () https://access.redhat.com/errata/RHSA-2024:1385 -
  • () https://access.redhat.com/errata/RHSA-2024:1386 -
  • () https://access.redhat.com/errata/RHSA-2024:1387 -
  • () https://access.redhat.com/errata/RHSA-2024:1388 -
  • () https://access.redhat.com/errata/RHSA-2024:1390 -
  • () https://access.redhat.com/errata/RHSA-2024:1391 -
  • () https://access.redhat.com/errata/RHSA-2024:1392 -
  • () https://access.redhat.com/errata/RHSA-2024:1393 -
  • () https://access.redhat.com/errata/RHSA-2024:1394 -

12 Mar 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 17:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2182

Mitre link : CVE-2024-2182

CVE.ORG link : CVE-2024-2182


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error