A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
{
"binaries": [
{
"binary_name": "ovn-central",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-common",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-controller-vtep",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-docker",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-host",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-ic",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
},
{
"binary_name": "ovn-ic-db",
"binary_version": "20.03.2-0ubuntu0.20.04.6"
}
]
}
{
"binaries": [
{
"binary_name": "ovn-central",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-common",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-controller-vtep",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-docker",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-host",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-ic",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
},
{
"binary_name": "ovn-ic-db",
"binary_version": "22.03.8-0ubuntu0.22.04.1"
}
]
}
{
"binaries": [
{
"binary_name": "ovn-central",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-common",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-controller-vtep",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-docker",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-host",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-ic",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
},
{
"binary_name": "ovn-ic-db",
"binary_version": "24.03.6-0ubuntu0.24.04.1"
}
]
}
{
"binaries": [
{
"binary_name": "ovn-central",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-common",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-controller-vtep",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-docker",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-host",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-ic",
"binary_version": "25.09.0-1"
},
{
"binary_name": "ovn-ic-db",
"binary_version": "25.09.0-1"
}
]
}
{
"binaries": [
{
"binary_name": "ovn-central",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-common",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-controller-vtep",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-docker",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-host",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-ic",
"binary_version": "26.03.0-2"
},
{
"binary_name": "ovn-ic-db",
"binary_version": "26.03.0-2"
}
]
}