{"schema_version":"1.9.0","id":"CVE-2023-3153","published":"2023-10-04T11:13:40.083Z","modified":"2026-08-12T13:34:25.435355Z","related":["SUSE-SU-2023:3710-1","SUSE-SU-2026:0280-1","SUSE-SU-2026:0290-1","openSUSE-SU-2024:13206-1"],"summary":"Service monitor mac flow is not rate limited","details":"A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ovn-org/ovn","events":[{"introduced":"0"},{"fixed":"e973969e779f8bff3e450745284c67cb648d2dd5"},{"introduced":"cb34bf2b9529f96c3d6dc3e9afa818101db6f0ec"},{"fixed":"f60f6f9aaa7ec38885137ee1f6299a10da003385"},{"introduced":"cd81684820b47ab07667637f726e1fd2a81e06a7"},{"fixed":"c851fe0931b627c0ceb96272520a10927f10c535"},{"introduced":"daa3d8b9d8225f1fdccc0297dce38ca8428f813b"},{"fixed":"ba5710edbfc8b11eb83500eb7da0beb39b955273"},{"introduced":"05d20a51032d65b6eed0c499cbb56ddbde5c754d"},{"fixed":"a20f880efdba9dcf19c1df77b31a3b8b9dffa345"},{"fixed":"9a3f7ed905e525ebdcb14541e775211cbb0203bd"}],"database_specific":{"cpe":"cpe:2.3:a:ovn:open_virtual_network:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"22.03.3"},{"introduced":"22.03.4"},{"fixed":"22.09.2"},{"introduced":"22.09.3"},{"fixed":"22.12.1"},{"introduced":"22.12.2"},{"fixed":"23.03.1"},{"introduced":"23.03.2"},{"fixed":"23.06.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v23.06.0","v23.03.0","v22.09.1","v22.03.2","v22.12.0","v22.09.0","v22.03.1","v22.03.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3153.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"100707879268515689071228807156796924197","length":1612},"id":"CVE-2023-3153-7f2ceda7","signature_type":"Function","signature_version":"v1","source":"https://github.com/ovn-org/ovn/commit/9a3f7ed905e525ebdcb14541e775211cbb0203bd","target":{"file":"northd/northd.c","function":"build_lswitch_destination_lookup_bmcast"}},{"deprecated":false,"digest":{"line_hashes":["50986681710720372360707408566068477418","252480662219656878439145177761545982267","142032261047848354833506823247262358887","329164269853397579377214380351543625034"],"threshold":0.9},"id":"CVE-2023-3153-a165b368","signature_type":"Line","signature_version":"v1","source":"https://github.com/ovn-org/ovn/commit/9a3f7ed905e525ebdcb14541e775211cbb0203bd","target":{"file":"lib/copp.c"}},{"deprecated":false,"digest":{"line_hashes":["273984248180741880940998914494089443661","203185577382962333624321689680785327007","155368957386231067524344954408589049656","253753055849551589332896634626431003037"],"threshold":0.9},"id":"CVE-2023-3153-d78e6bf9","signature_type":"Line","signature_version":"v1","source":"https://github.com/ovn-org/ovn/commit/9a3f7ed905e525ebdcb14541e775211cbb0203bd","target":{"file":"lib/copp.h"}},{"deprecated":false,"digest":{"line_hashes":["130994271946306197769789664995555076929","200663036279558230899598810320786448335","257927616725762713937645602867735527471","13358029243250610857060806115376031208","236156749985826493025022585418312343674","295079638578447228654133263734781380464"],"threshold":0.9},"id":"CVE-2023-3153-f4ba0918","signature_type":"Line","signature_version":"v1","source":"https://github.com/ovn-org/ovn/commit/9a3f7ed905e525ebdcb14541e775211cbb0203bd","target":{"file":"northd/northd.c"}}],"vanir_signatures_modified":"2026-08-12T13:34:25Z"}}],"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://mail.openvswitch.org/pipermail/ovs-announce/2023-August/000327.html"},{"type":"WEB","url":"https://mail.openvswitch.org/pipermail/ovs-dev/2023-August/407553.html"},{"type":"WEB","url":"https://packages.fedoraproject.org/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-3153"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3153.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3153"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2213279"},{"type":"REPORT","url":"https://github.com/ovn-org/ovn/issues/198"},{"type":"FIX","url":"https://github.com/ovn-org/ovn/commit/9a3f7ed905e525ebdcb14541e775211cbb0203bd"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3153.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}