CVE-2023-3153

Publication date 4 October 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.

Status

Package Ubuntu Release Status
ovn 23.10 mantic
Not affected
23.04 lunar
Fixed 23.03.1-1ubuntu0.23.04.1
22.10 kinetic Ignored end of life, was deferred [2023-08-22]
22.04 LTS jammy
Fixed 22.03.3-0ubuntu0.22.04.1
20.04 LTS focal Ignored end of standard support, was ignored [change too intrusive]
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ovn

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.3 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L


Access our resources on patching vulnerabilities