CVE-2023-3966
HIGHOpenvswitch < 3.1.0 - Denial of Service
Title source: ruleDescription
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
References (4)
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-248
Status
published
Affected Products (3)
openvswitch/openvswitch
< 3.1.0
fedoraproject/fedora
fedoraproject/fedora
Timeline
Published
Feb 22, 2024
Tracked Since
Feb 18, 2026