CVE-2024-2182
6.5
MEDIUM
CVSS 3.1
EPSS 0.78%
Description
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.
How to fix CVE-2024-2182
To remediate CVE-2024-2182, upgrade the affected package to a fixed version below.
- Debian/ovn—upgrade to 23.03.1-1~deb12u2 or later
Is CVE-2024-2182 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 23.03.1-1~deb12u2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |