SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-1668

A flaw was found in openvswitch (OVS).

HIGH 8.2EPSS 1.22%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS
1.22% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-670
Affected
cloudbase/open vswitch · debian/debian linux · redhat/openshift container platform · redhat/openstack platform · redhat/virtualization · redhat/fast datapath
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.