CVE-2020-27827Uncontrolled Resource Consumption in Openvswitch

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

CVEListV5lldp/openvswitchlldpd 1.0.8, openvswitch 2.14.1, openvswitch 2.13.2, openvswitch 2.12.2, openvswitch 2.11.5, openvswitch 2.10.6, openvswitch 2.9.8, openvswitch 2.8.10, openvswitch 2.7.12, openvswitch 2.6.9
NVDlldpd_project/lldpd< 1.0.8
NVDopenvswitch/openvswitch2.6.02.6.9+8
Debianlldpd_project/lldpd< 1.0.8-1+3
Debianopenvswitch/openvswitch< 2.15.0~git20210104.def6eb1ea+dfsg1-4+3

Also affects: Fedora 33, Enterprise Linux 7.0, 8.0, Openshift Container Platform 4.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m3mq-x6x3-4537: A flaw was found in multiple versions of OpenvSwitch2022-05-24
OSV
CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch2021-03-18
CVEList
CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch2021-03-18

📋Vendor Advisories

4
Microsoft
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of s2021-03-09
Ubuntu
Open vSwitch vulnerabilities2021-01-13
Red Hat
lldp/openvswitch: denial of service via externally triggered memory leak2021-01-13
Debian
CVE-2020-27827: lldpd - A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP pac...2020