CVE-2016-2074
published 2016-07-03CVE-2016-2074: Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary…
PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.28%
92.8th percentile
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 2.3.0+git20140819-4 (bookworm) | openvswitch 2.3.0+git20140819-4 (bookworm) |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | >= 0 < 2.3.0+git20140819-4 | 2.3.0+git20140819-4 |
| openvswitch | openvswitch | >= 0 < 2.3.0+git20140819-4 | 2.3.0+git20140819-4 |
| openvswitch | openvswitch | >= 0 < 2.3.0+git20140819-4 | 2.3.0+git20140819-4 |
| openvswitch | openvswitch | >= 0 < 2.3.0+git20140819-4 | 2.3.0+git20140819-4 |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xfh5-4xfg-3g5f: Buffer overflow in lib/flow
ghsa_unreviewed·2022-05-14
CVE-2016-2074 [CRITICAL] CWE-119 GHSA-xfh5-4xfg-3g5f: Buffer overflow in lib/flow
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
OSV
CVE-2016-2074: Buffer overflow in lib/flow
osv·2016-07-03·CVSS 9.8
CVE-2016-2074 [CRITICAL] CVE-2016-2074: Buffer overflow in lib/flow
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
Red Hat
openvswitch: MPLS buffer overflow vulnerability
vendor_redhat·2016-03-28·CVSS 9.8
CVE-2016-2074 [CRITICAL] CWE-121 openvswitch: MPLS buffer overflow vulnerability
openvswitch: MPLS buffer overflow vulnerability
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
A buffer overflow flaw was discovered in the OVS processing of MPLS labels. A remote attacker able to deliver a frame containing a malicious MPLS label that would be processed by OVS could trigger the flaw and use the resulting memory corruption to cause a denial of service (DoS) or, possibly, execute arbitrary code.
Package: openvswitch (Red Hat OpenStack Platform 8 (Liberty)) - Not affected
Package: openvswitch-dpdk (Red Hat OpenStack Platform 8 (Liberty)) - Not affected
Debian
CVE-2016-2074: openvswitch - Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x be...
vendor_debian·2016·CVSS 9.8
CVE-2016-2074 [CRITICAL] CVE-2016-2074: openvswitch - Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x be...
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
Scope: local
bookworm: resolved (fixed in 2.3.0+git20140819-4)
bullseye: resolved (fixed in 2.3.0+git20140819-4)
forky: resolved (fixed in 2.3.0+git20140819-4)
sid: resolved (fixed in 2.3.0+git20140819-4)
trixie: resolved (fixed in 2.3.0+git20140819-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [rdo]
bugzilla·2016-04-28·CVSS 9.8
CVE-2016-2074 [CRITICAL] CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [rdo]
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [rdo]
Cloning to RDO where we ship openvswitch until it hits baseOS in RHEL 7.3
Same as Fedora, we're updating to 2.5 which is not vulnerable.
+++ This bug was initially created as a clone of Bug #1321946 +++
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
--- Additional comment from Panu Matilainen on 2016-03-29 09:04:48 EDT ---
In Fedora this gets handled via update to OVS 2.5. The CVE details were not known at the time these updates were submitted, but since OVS 2.5 is not vulnerable then these suffice as the fix:
Discussio
Bugzilla
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [fedora-all]
bugzilla·2016-03-29·CVSS 9.8
CVE-2016-2074 [CRITICAL] CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [fedora-all]
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability
bugzilla·2016-03-17·CVSS 9.8
CVE-2016-2074 [CRITICAL] CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability
CVE-2016-2074 openvswitch: MPLS buffer overflow vulnerability
Multiple versions of Open vSwitch are vulnerable to remote buffer
overflow attacks, in which crafted MPLS packets could overflow the
buffer reserved for MPLS labels in an OVS internal data structure.
The MPLS packets that trigger the vulnerability and the potential for
exploitation vary depending on version:
- Open vSwitch 2.1.x and earlier are not vulnerable.
- In Open vSwitch 2.2.x and 2.3.x, the MPLS buffer overflow can be
exploited for arbitrary remote code execution.
- In Open vSwitch 2.4.x, the MPLS buffer overflow does not
obviously lead to a remote code execution exploit, but testing
shows that it can allow a remote denial of service.
- Open vSwitch 2.5.x is not vulnerable.
Mitigation
For any version of Open vSwit
http://openvswitch.org/pipermail/announce/2016-March/000082.htmlhttp://openvswitch.org/pipermail/announce/2016-March/000083.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0523.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0524.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0537.htmlhttp://www.debian.org/security/2016/dsa-3533http://www.securityfocus.com/bid/85700https://access.redhat.com/errata/RHSA-2016:0615https://bugzilla.redhat.com/show_bug.cgi?id=1318553https://security-tracker.debian.org/tracker/CVE-2016-2074https://security.gentoo.org/glsa/201701-07https://support.citrix.com/article/CTX232655http://openvswitch.org/pipermail/announce/2016-March/000082.htmlhttp://openvswitch.org/pipermail/announce/2016-March/000083.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0523.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0524.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0537.htmlhttp://www.debian.org/security/2016/dsa-3533http://www.securityfocus.com/bid/85700https://access.redhat.com/errata/RHSA-2016:0615https://bugzilla.redhat.com/show_bug.cgi?id=1318553https://security-tracker.debian.org/tracker/CVE-2016-2074https://security.gentoo.org/glsa/201701-07https://support.citrix.com/article/CTX232655
2016-07-03
Published