CVE-2018-17206

CWE-125Out-of-bounds Read10 documents8 sources
Severity
4.9MEDIUM
EPSS
2.1%
top 16.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 13

Description

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

Debianopenvswitch< 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1+3
NVDopenvswitch/openvswitch2.7.02.7.6
NVDredhat/openstack10, 13+1

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04, 18.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-pcf7-fwpx-5mr2: An issue was discovered in Open vSwitch (OvS) 22022-05-13
OSV
openvswitch vulnerabilities2019-01-30
OSV
CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 22018-09-19
CVEList
CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 22018-09-19

📋Vendor Advisories

3
Ubuntu
Open vSwitch vulnerabilities2019-01-30
Red Hat
openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()2018-09-25
Debian
CVE-2018-17206: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bu...2018

💬Community

2
Bugzilla
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()2018-09-25
Bugzilla
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle() [openstack-rdo]2018-09-25