---
title: "CVE-2023-28841\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-28841?format=md
keywords: index, follow
---

# CVE-2023-28841

Publication date 4 April 2023

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.8 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2023-28841?format=md#impact-score)

Toggle side navigation

## Description

Moby is an open source container framework developed by Docker Inc. that is
distributed as Docker, Mirantis Container Runtime, and various other
downstream projects/products. The Moby daemon component (`dockerd`), which
is developed as moby/moby is commonly referred to as \*Docker\*.
Swarm Mode, which is compiled in and delivered by default in `dockerd` and
is thus present in most major Moby downstreams, is a simple, built-in
container orchestrator that is implemented through a combination of
SwarmKit and supporting network code.
The `overlay` network driver is a core feature of Swarm Mode, providing
isolated virtual LANs that allow communication between containers and
services across the cluster. This driver is an implementation/user of
VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams
that tag the frame with the VXLAN metadata, including a VXLAN Network ID
(VNI) that identifies the originating overlay network. In addition, the
overlay network driver supports an optional, off-by-default encrypted mode,
which is especially useful when VXLAN packets traverses an untrusted
network between nodes.
Encrypted overlay networks function by encapsulating the VXLAN datagrams
through the use of the IPsec Encapsulating Security Payload protocol in
Transport mode. By deploying IPSec encapsulation, encrypted overlay
networks gain the additional properties of source authentication through
cryptographic proof, data integrity through check-summing, and
confidentiality through encryption.
When setting an endpoint up on an encrypted overlay network, Moby installs
three iptables (Linux kernel firewall) rules that enforce both incoming and
outgoing IPSec. These rules rely on the `u32` iptables extension provided
by the `xt\_u32` kernel module to directly filter on a VXLAN packet's VNI
field, so that IPSec guarantees can be enforced on encrypted overlay
networks without interfering with other overlay networks or other users of
VXLAN.
An iptables rule designates outgoing VXLAN datagrams with a VNI that
corresponds to an encrypted overlay network for IPsec encapsulation.
Encrypted overlay networks on affected platforms silently transmit
unencrypted data. As a result, `overlay` networks may appear to be
functional, passing traffic as expected, but without any of the expected
confidentiality or data integrity guarantees.
It is possible for an attacker sitting in a trusted position on the network
to read all of the application traffic that is moving across the overlay
network, resulting in unexpected secrets or user data disclosure. Thus,
because many database protocols, internal APIs, etc. are not protected by a
second layer of encryption, a user may use Swarm encrypted overlay networks
to provide confidentiality, which due to this vulnerability this is no
longer guaranteed.
Patches are available in Moby releases 23.0.3, and 20.10.24. As Mirantis
Container Runtime's 20.10 releases are numbered differently, users of that
platform should update to 20.10.16.
Some workarounds are available. Close the VXLAN port (by default, UDP port
4789) to outgoing traffic at the Internet boundary in order to prevent
unintentionally leaking unencrypted traffic over the Internet, and/or
ensure that the `xt\_u32` kernel module is available on all nodes of the
Swarm cluster.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2023-28841?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| docker.io | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Fixed 20.10.21-0ubuntu1~22.04.7+esm2  Ubuntu Pro |
| 20.04 LTS focal | Fixed 20.10.21-0ubuntu1~20.04.6+esm2  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 20.10.21-0ubuntu1~18.04.3+esm3  Ubuntu Pro |
| 16.04 LTS xenial | Vulnerable |
| docker.io-app | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Fixed 27.5.1-0ubuntu3~22.04.2 |
| 20.04 LTS focal | Fixed 26.1.3-0ubuntu1~20.04.1+esm1  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [vyomydv](https://launchpad.net/~vyomydv)

`docker.io-app` for `focal` is fixed in 24.0.7-0ubuntu2~20.04.1
in `updates` pocket.
`docker.io-app` for `jammy` is fixed in 24.0.7-0ubuntu2~22.04.1
in `updates` pocket.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.8 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.8 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28841)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-28841)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-28841)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-28841)

### Related Ubuntu Security Notices (USN)

+ [USN-7474-1](https://usn.ubuntu.com/USN-7474-1)
+ Docker vulnerabilities
+ 1 May 2025

### Other references

* <https://github.com/moby/moby/security/advisories/GHSA-6wrf-mxfj-pf5p>
* <https://github.com/moby/libnetwork/security/advisories/GHSA-gvm4-2qqg-m333>
* <https://github.com/moby/moby/issues/43382>
* <https://github.com/moby/moby/security/advisories/GHSA-232p-vwff-86mp>
* <https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw>
* <https://github.com/moby/moby/security/advisories/GHSA-33pg-m6jh-5237>
* <https://github.com/moby/moby/pull/45118>
* <https://github.com/moby/libnetwork/blob/d9fae4c73daf76c3b0f77e14b45b8bf612ba764d/drivers/overlay/encryption.go#L205-L207>
* <https://www.cve.org/CVERecord?id=CVE-2023-28841>
