CVE-2018-17204
published 2018-09-19CVE-2018-17204: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.91%
77.6th percentile
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openvswitch | < openvswitch 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 (bookworm) | openvswitch 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 (bookworm) |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.5.5-0ubuntu0.16.04.2 | 2.5.5-0ubuntu0.16.04.2 |
| openvswitch | openvswitch | >= 0 < 2.9.2-0ubuntu0.18.04.3 | 2.9.2-0ubuntu0.18.04.3 |
| openvswitch | openvswitch | 2.7.0 – 2.7.6 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wv2-475w-c2fw: An issue was discovered in Open vSwitch (OvS) 2
ghsa_unreviewed·2022-05-13
CVE-2018-17204 [MEDIUM] CWE-617 GHSA-4wv2-475w-c2fw: An issue was discovered in Open vSwitch (OvS) 2
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
OSV
openvswitch vulnerabilities
osv·2019-01-30·CVSS 4.3
CVE-2018-17204 [MEDIUM] openvswitch vulnerabilities
openvswitch vulnerabilities
It was discovered that Open vSwitch incorrectly decoded certain packets. A
remote attacker could possibly use this issue to cause Open vSwitch to
crash, resulting in a denial of service. (CVE-2018-17204)
It was discovered that Open vSwitch incorrectly handled processing certain
flows. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-17205)
It was discovered that Open vSwitch incorrectly handled BUNDLE action
decoding. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. (CVE-2018-17206)
OSV
CVE-2018-17204: An issue was discovered in Open vSwitch (OvS) 2
osv·2018-09-19·CVSS 4.3
CVE-2018-17204 [MEDIUM] CVE-2018-17204: An issue was discovered in Open vSwitch (OvS) 2
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2019-01-30·CVSS 4.3
CVE-2018-17204 [MEDIUM] Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
It was discovered that Open vSwitch incorrectly decoded certain packets. A
remote attacker could possibly use this issue to cause Open vSwitch to
crash, resulting in a denial of service. (CVE-2018-17204)
It was discovered that Open vSwitch incorrectly handled processing certain
flows. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-17205)
It was discovered that Open vSwitch incorrectly handled BUNDLE action
decoding. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. (CVE-2018-17206)
Instructions: In general, a
Red Hat
openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
vendor_redhat·2018-09-25·CVSS 4.3
CVE-2018-17204 [MEDIUM] CWE-20 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
An issue was discovered in Open vSwitch (OvS), 2.4.x through 2.4.1, 2.5.x through 2.5.5, 2.6.x through 2.6.3, 2.7.x through 2.7.6, 2.8.x through 2.8.4, and2.9.x through 2.9.2, affecting the parse_group_pr
Debian
CVE-2018-17204: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting par...
vendor_debian·2018·CVSS 4.3
CVE-2018-17204 [MEDIUM] CVE-2018-17204: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting par...
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Scope: local
bookworm: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
bullseye: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
forky: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
sid: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
trixie: resolved (fixed in 2.10.0+2018.08.28+git.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
bugzilla·2018-09-25·CVSS 4.3
CVE-2018-17204 [MEDIUM] CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Upstream Patch:
https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: openstack-rdo
Bugzilla
CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure [openstack-rdo]
bugzilla·2018-09-25·CVSS 4.3
CVE-2018-17204 [MEDIUM] CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure [openstack-rdo]
CVE-2018-17204 openvswitch: Mishandle of group mods in lib/ofp-util.c:parse_group_prop_ntr_selection_method() allows for assertion failure [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
https://access.redhat.com/errata/RHSA-2018:3500https://access.redhat.com/errata/RHSA-2019:0053https://access.redhat.com/errata/RHSA-2019:0081https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cdehttps://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://usn.ubuntu.com/3873-1/https://access.redhat.com/errata/RHSA-2018:3500https://access.redhat.com/errata/RHSA-2019:0053https://access.redhat.com/errata/RHSA-2019:0081https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cdehttps://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://usn.ubuntu.com/3873-1/
2018-09-19
Published