CVE-2024-2182

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
redhatCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Debian logo
Debian Releases
Debian Product
Codename
ovn
bookworm
23.03.1-1~deb12u2
fixed
sid
25.03.0-1
fixed
trixie
25.03.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ovn
noble
not-affected
mantic
Fixed 23.09.0-1ubuntu0.1
released
jammy
Fixed 22.03.3-0ubuntu0.22.04.2
released
focal
Fixed 20.03.2-0ubuntu0.20.04.5
released
References