Severity
7.5HIGH
EPSS
0.8%
top 26.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 13

Description

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows that were successfully applied from the same bundle. This is possible since OvS maintains list of old flows that were replaced by flows from the bundl

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debianopenvswitch< 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1+3
Ubuntuopenvswitch< 2.5.5-0ubuntu0.16.04.2+1
NVDopenvswitch/openvswitch2.7.02.7.6
NVDredhat/openstack10, 13+1

Also affects: Ubuntu Linux 16.04, 18.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-vxv4-rrx9-5xfq: An issue was discovered in Open vSwitch (OvS) 22022-05-13
OSV
openvswitch vulnerabilities2019-01-30
CVEList
CVE-2018-17205: An issue was discovered in Open vSwitch (OvS) 22018-09-19
OSV
CVE-2018-17205: An issue was discovered in Open vSwitch (OvS) 22018-09-19

📋Vendor Advisories

3
Ubuntu
Open vSwitch vulnerabilities2019-01-30
Red Hat
openvswitch: Error during bundle commit in ofproto/ofproto.c:ofproto_rule_insert__() allows for crash2018-09-25
Debian
CVE-2018-17205: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofp...2018

💬Community

2
Bugzilla
CVE-2018-17205 openvswitch: Error during bundle commit in ofproto/ofproto.c:ofproto_rule_insert__() allows for crash2018-09-25
Bugzilla
CVE-2018-17205 openvswitch: Error during bundle commit in ofproto/ofproto.c:ofproto_rule_insert__() allows for crash [openstack-rdo]2018-09-25