Marius Berntsberg, Trygve Vea, Tore Anderson, Rodolfo Alonso, Jay Faulkner, and Brian Haley discovered that OVN incorrectly handled certain crafted UDP packets. A remote attacker could possibly use this issue to bypass egress ACL rules.
{ "binaries": [ { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-central" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-common" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-controller-vtep" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-docker" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-host" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-ic" }, { "binary_version": "20.03.2-0ubuntu0.20.04.6", "binary_name": "ovn-ic-db" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-central" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-common" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-controller-vtep" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-docker" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-host" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-ic" }, { "binary_version": "22.03.3-0ubuntu0.22.04.5", "binary_name": "ovn-ic-db" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-central" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-common" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-controller-vtep" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-docker" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-host" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-ic" }, { "binary_version": "24.03.2-0ubuntu0.24.04.2", "binary_name": "ovn-ic-db" } ], "availability": "No subscription required" }