CVE-2020-27827 — Uncontrolled Resource Consumption in Openvswitch
Severity
7.5HIGHNVD
EPSS
0.4%
top 38.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateMay 24
Description
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages10 packages
▶CVEListV5lldp/openvswitchlldpd 1.0.8, openvswitch 2.14.1, openvswitch 2.13.2, openvswitch 2.12.2, openvswitch 2.11.5, openvswitch 2.10.6, openvswitch 2.9.8, openvswitch 2.8.10, openvswitch 2.7.12, openvswitch 2.6.9
Also affects: Fedora 33, Enterprise Linux 7.0, 8.0, Openshift Container Platform 4.0
Patches
🔴Vulnerability Details
3📋Vendor Advisories
4Microsoft▶
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of s↗2021-03-09
Debian▶
CVE-2020-27827: lldpd - A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP pac...↗2020