Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-2182

Published: 12 March 2024

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

Notes

AuthorNote
seth-arnold
patches are in this message on distros:
Message-ID: <cf2854ab-8804-4316-908d-130108456f55@redhat.com>

Priority

Medium

Status

Package Release Status
ovn
Launchpad, Ubuntu, Debian
focal
Released (20.03.2-0ubuntu0.20.04.5)
jammy
Released (22.03.3-0ubuntu0.22.04.2)
mantic
Released (23.09.0-1ubuntu0.1)
upstream Pending
(v22.03.7, v23.03.3, v23.06.3, v23.09.3, v24.03.1)