CVE-2024-2182
Publication date 12 March 2024
Last updated 30 May 2025
Ubuntu priority
Cvss 3 Severity Score
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
Status
Package | Ubuntu Release | Status |
---|---|---|
ovn | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Fixed 22.03.3-0ubuntu0.22.04.2
|
|
20.04 LTS focal |
Fixed 20.03.2-0ubuntu0.20.04.5
|
Notes
seth-arnold
patches are in this message on distros: Message-ID: <cf2854ab-8804-4316-908d-130108456f55@redhat.com>
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6691-1
- OVN vulnerability
- 12 March 2024