CVE-2017-9214
published 2017-05-23CVE-2017-9214: In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned…
PriorityP340critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.89%
85.3th percentile
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openvswitch | < openvswitch 2.8.1+dfsg1-2 (bookworm) | openvswitch 2.8.1+dfsg1-2 (bookworm) |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.5.2-0ubuntu0.16.04.2 | 2.5.2-0ubuntu0.16.04.2 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization_manager | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 9.8
CVE-2017-9214 [CRITICAL] Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
Bhargava Shastry discovered that Open vSwitch incorrectly handled certain
OFP messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9214)
It was discovered that Open vSwitch incorrectly handled certain OpenFlow
role messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9263)
It was discovered that Open vSwitch incorrectly handled certain malformed
packets. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 17.04. (CVE-2017-9264)
It was dis
Red Hat
openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
vendor_redhat·2017-05-20·CVSS 9.8
CVE-2017-9214 [CRITICAL] CWE-190 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
An unsigned integer wrap around that led to a buffer over-read was found when parsing OFPT_QUEUE_GET_CONFIG_REPLY messages in Open vSwitch (OvS). An attacker could use this issue to cause a remote denial of service attack.
Package: openvswitch (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: openvswitch (Red Hat OpenShift Enterprise 3) - Not affected
Package: openvswitch (Red Hat OpenStack Platform 12 (Pike)) - Not affected
Debian
CVE-2017-9214: openvswitch - In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type O...
vendor_debian·2017·CVSS 9.8
CVE-2017-9214 [CRITICAL] CVE-2017-9214: openvswitch - In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type O...
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
Scope: local
bookworm: resolved (fixed in 2.8.1+dfsg1-2)
bullseye: resolved (fixed in 2.8.1+dfsg1-2)
forky: resolved (fixed in 2.8.1+dfsg1-2)
sid: resolved (fixed in 2.8.1+dfsg1-2)
trixie: resolved (fixed in 2.8.1+dfsg1-2)
GHSA
GHSA-6q3f-fc2p-9rh3: In Open vSwitch (OvS) 2
ghsa_unreviewed·2022-05-13
CVE-2017-9214 [CRITICAL] CWE-191 GHSA-6q3f-fc2p-9rh3: In Open vSwitch (OvS) 2
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
OSV
openvswitch vulnerabilities
osv·2017-10-11·CVSS 9.8
CVE-2017-9214 [CRITICAL] openvswitch vulnerabilities
openvswitch vulnerabilities
Bhargava Shastry discovered that Open vSwitch incorrectly handled certain
OFP messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9214)
It was discovered that Open vSwitch incorrectly handled certain OpenFlow
role messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9263)
It was discovered that Open vSwitch incorrectly handled certain malformed
packets. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 17.04. (CVE-2017-9264)
It was discovered that Open vSwitch incorrectly handled group mod OpenFlow
messa
OSV
CVE-2017-9214: In Open vSwitch (OvS) 2
osv·2017-05-23·CVSS 9.8
CVE-2017-9214 [CRITICAL] CVE-2017-9214: In Open vSwitch (OvS) 2
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
bugzilla·2017-05-30·CVSS 9.8
CVE-2017-9214 [CRITICAL] CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
A vulnerability in openvswitch was found. While parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332711.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 9.0 (Mita
Bugzilla
CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
bugzilla·2017-05-30·CVSS 8.8
CVE-2016-10377 [HIGH] CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
https://access.redhat.com/errata/RHSA-2017:2418https://access.redhat.com/errata/RHSA-2017:2553https://access.redhat.com/errata/RHSA-2017:2648https://access.redhat.com/errata/RHSA-2017:2665https://access.redhat.com/errata/RHSA-2017:2692https://access.redhat.com/errata/RHSA-2017:2698https://access.redhat.com/errata/RHSA-2017:2727https://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332711.htmlhttps://access.redhat.com/errata/RHSA-2017:2418https://access.redhat.com/errata/RHSA-2017:2553https://access.redhat.com/errata/RHSA-2017:2648https://access.redhat.com/errata/RHSA-2017:2665https://access.redhat.com/errata/RHSA-2017:2692https://access.redhat.com/errata/RHSA-2017:2698https://access.redhat.com/errata/RHSA-2017:2727https://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332711.html
2017-05-23
Published