The vendor explicitly identifies these products as affected by this CVE.
- ovn23.03 as a component of Fast Datapath for RHEL 8
- ovn23.03-central as a component of Fast Datapath for RHEL 8
- ovn23.03-host as a component of Fast Datapath for RHEL 8
- ovn23.03-vtep as a component of Fast Datapath for RHEL 8
- ovn23.03.src as a component of Fast Datapath for RHEL 8
- ovn-2021-central as a component of Fast Datapath for RHEL 9
- ovn-2021-host as a component of Fast Datapath for RHEL 9
- ovn-2021-vtep as a component of Fast Datapath for RHEL 9
- ovn-2021.src as a component of Fast Datapath for RHEL 9
- ovn23.03 as a component of Fast Datapath for RHEL 9
- ovn23.03-central as a component of Fast Datapath for RHEL 9
- ovn23.03-host as a component of Fast Datapath for RHEL 9
- Summary
- A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
