CVE-2025-0650

A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.
Configurations

No configuration.

History

06 Feb 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:1083 -
  • () https://access.redhat.com/errata/RHSA-2025:1084 -
  • () https://access.redhat.com/errata/RHSA-2025:1085 -
  • () https://access.redhat.com/errata/RHSA-2025:1086 -
  • () https://access.redhat.com/errata/RHSA-2025:1087 -
  • () https://access.redhat.com/errata/RHSA-2025:1088 -
  • () https://access.redhat.com/errata/RHSA-2025:1089 -
  • () https://access.redhat.com/errata/RHSA-2025:1090 -
  • () https://access.redhat.com/errata/RHSA-2025:1091 -
  • () https://access.redhat.com/errata/RHSA-2025:1092 -
  • () https://access.redhat.com/errata/RHSA-2025:1093 -
  • () https://access.redhat.com/errata/RHSA-2025:1094 -
  • () https://access.redhat.com/errata/RHSA-2025:1095 -
  • () https://access.redhat.com/errata/RHSA-2025:1096 -
  • () https://access.redhat.com/errata/RHSA-2025:1097 -
Summary
  • (es) Se encontró una falla en Open Virtual Network (OVN). Los paquetes UDP manipulados en particular pueden eludir las listas de control de acceso (ACL) de salida en instalaciones OVN configuradas con un conmutador lógico con registros DNS configurados en él y si el mismo conmutador tiene alguna ACL de salida configurada. Este problema puede provocar acceso no autorizado a máquinas virtuales y contenedores que se ejecutan en la red OVN.

23 Jan 2025, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/01/22/11 -

23 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 17:15

Updated : 2025-02-06 09:15


NVD link : CVE-2025-0650

Mitre link : CVE-2025-0650

CVE.ORG link : CVE-2025-0650


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control