CVE-2017-14970
published 2017-10-02CVE-2017-14970: In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor…
PriorityP424medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.24%
65.9th percentile
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 2.8.1+dfsg1-2 (bookworm) | openvswitch 2.8.1+dfsg1-2 (bookworm) |
| openvswitch | openvswitch | <= 2.8.0 | — |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
vendor_redhat·2017-09-21·CVSS 5.9
CVE-2017-14970 [MEDIUM] CWE-400 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Statement: Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.
Package: openvswitch (Fast Datapath for RHEL 7) - Not affected
Package: openvswitch (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - No
Debian
CVE-2017-14970: openvswitch - In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory ...
vendor_debian·2017·CVSS 5.9
CVE-2017-14970 [MEDIUM] CVE-2017-14970: openvswitch - In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory ...
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Scope: local
bookworm: resolved (fixed in 2.8.1+dfsg1-2)
bullseye: resolved (fixed in 2.8.1+dfsg1-2)
forky: resolved (fixed in 2.8.1+dfsg1-2)
sid: resolved (fixed in 2.8.1+dfsg1-2)
trixie: resolved (fixed in 2.8.1+dfsg1-2)
GHSA
GHSA-jjh9-mpf5-64ww: In lib/ofp-util
ghsa_unreviewed·2022-05-13
CVE-2017-14970 [MEDIUM] CWE-772 GHSA-jjh9-mpf5-64ww: In lib/ofp-util
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
OSV
CVE-2017-14970: In lib/ofp-util
osv·2017-10-02·CVSS 5.9
CVE-2017-14970 [MEDIUM] CVE-2017-14970: In lib/ofp-util
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages [fedora-all]
bugzilla·2017-10-03·CVSS 5.9
CVE-2017-14970 [MEDIUM] CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages [fedora-all]
CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
bugzilla·2017-10-03·CVSS 5.9
CVE-2017-14970 [MEDIUM] CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
CVE-2017-14970 openvswitch: Multiple memory leaks in lib/ofp-util.c while parsing malformed OpenFlow group mod messages
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. An attacker can use this for a Denial of Service.
Upstream fixes:
https://github.com/openvswitch/ovs/commit/77ad4225d125030420d897c873e4734ac708c66b
https://github.com/openvswitch/ovs/commit/f673f4059717dc9d2d6dd2d4db52be1149a996dd
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1497967]
---
Analysis: Currently when parsing group mod messages, particularly group descriptor messages and those that contain buckets, the buckets will be loaded into memory. If for some reason the parsing fails
2017-10-02
Published