ubuntu · CVE-2023-5366

Quick triage

Priority: medium Published: 2023-10-06 18:15:00 UTC Updated: 2025-08-19 22:10:17 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-5366 medium priority: Ubuntu including 1 source packages (openvswitch), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 8, ignored 3, needed 1.

Description:

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

cvelogic Threat Intelligence