CVE-2018-17206
published 2018-09-19CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue…
PriorityP422medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.05%
79.1th percentile
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openvswitch | < openvswitch 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 (bookworm) | openvswitch 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 (bookworm) |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 | 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 |
| openvswitch | openvswitch | >= 0 < 2.5.5-0ubuntu0.16.04.2 | 2.5.5-0ubuntu0.16.04.2 |
| openvswitch | openvswitch | >= 0 < 2.9.2-0ubuntu0.18.04.3 | 2.9.2-0ubuntu0.18.04.3 |
| openvswitch | openvswitch | 2.7.0 – 2.7.6 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcf7-fwpx-5mr2: An issue was discovered in Open vSwitch (OvS) 2
ghsa_unreviewed·2022-05-13
CVE-2018-17206 [MEDIUM] CWE-125 GHSA-pcf7-fwpx-5mr2: An issue was discovered in Open vSwitch (OvS) 2
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
OSV
openvswitch vulnerabilities
osv·2019-01-30·CVSS 4.3
CVE-2018-17204 [MEDIUM] openvswitch vulnerabilities
openvswitch vulnerabilities
It was discovered that Open vSwitch incorrectly decoded certain packets. A
remote attacker could possibly use this issue to cause Open vSwitch to
crash, resulting in a denial of service. (CVE-2018-17204)
It was discovered that Open vSwitch incorrectly handled processing certain
flows. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-17205)
It was discovered that Open vSwitch incorrectly handled BUNDLE action
decoding. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. (CVE-2018-17206)
OSV
CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 2
osv·2018-09-19·CVSS 4.9
CVE-2018-17206 [MEDIUM] CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 2
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2019-01-30·CVSS 4.3
CVE-2018-17204 [MEDIUM] Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
It was discovered that Open vSwitch incorrectly decoded certain packets. A
remote attacker could possibly use this issue to cause Open vSwitch to
crash, resulting in a denial of service. (CVE-2018-17204)
It was discovered that Open vSwitch incorrectly handled processing certain
flows. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-17205)
It was discovered that Open vSwitch incorrectly handled BUNDLE action
decoding. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. (CVE-2018-17206)
Instructions: In general, a
Red Hat
openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
vendor_redhat·2018-09-25·CVSS 4.9
CVE-2018-17206 [MEDIUM] CWE-125 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
An issue was discovered in Open vSwitch (OvS) 2.5.x through 2.5.5, 2.6.x through 2.6.3, 2.7.x through 2.7.6, 2.8.x through 2.8.4, and 2.9.x through 2.9.2 where the decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
A specially crafted flow update applied using the bundling feature of Open vSwitch could potentially cause a crash leading to a denial of service.
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Not affected
Package: openvswitch2.10 (Fast Datapath fo
Debian
CVE-2018-17206: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bu...
vendor_debian·2018·CVSS 4.9
CVE-2018-17206 [MEDIUM] CVE-2018-17206: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bu...
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Scope: local
bookworm: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
bullseye: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
forky: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
sid: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
trixie: resolved (fixed in 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
bugzilla·2018-09-25·CVSS 4.9
CVE-2018-17206 [MEDIUM] CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle()
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Upstream Patch:
https://nvd.nist.gov/vuln/detail/CVE-2018-17206
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: openstack-rdo [bug 1632529]
---
I have downgraded the severity after review. This crash would be possible when bundling changes to the OVS flow table, which requires use of the local ovs-vsctl tool by a logged in administrative user, so network and unprivileged didn't quite seem to fit.
I have updated the flaw RHOSP edition impacts after reviewing both RHOSP and FDP releases, incl
Bugzilla
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle() [openstack-rdo]
bugzilla·2018-09-25·CVSS 4.9
CVE-2018-17206 [MEDIUM] CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle() [openstack-rdo]
CVE-2018-17206 openvswitch: Buffer over-read in lib/ofp-actions.c:decode_bundle() [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO is using ope
https://access.redhat.com/errata/RHSA-2018:3500https://access.redhat.com/errata/RHSA-2019:0053https://access.redhat.com/errata/RHSA-2019:0081https://github.com/openvswitch/ovs/commit/9237a63c47bd314b807cda0bd2216264e82edbe8https://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://usn.ubuntu.com/3873-1/https://access.redhat.com/errata/RHSA-2018:3500https://access.redhat.com/errata/RHSA-2019:0053https://access.redhat.com/errata/RHSA-2019:0081https://github.com/openvswitch/ovs/commit/9237a63c47bd314b807cda0bd2216264e82edbe8https://lists.debian.org/debian-lts-announce/2021/02/msg00032.htmlhttps://usn.ubuntu.com/3873-1/
2018-09-19
Published