CVE-2022-4337
published 2023-01-10CVE-2022-4337: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.32%
67.7th percentile
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openvswitch | < openvswitch 3.1.0~git20221212.739bcf2-4 (bookworm) | openvswitch 3.1.0~git20221212.739bcf2-4 (bookworm) |
| msrc | cbl2_openvswitch_2.17.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_openvswitch_2.15.7-1_on_cbl_mariner_1.0 | — | — |
| openvswitch | openvswitch | < 2.13.10 | 2.13.10 |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-2+deb11u2 | 2.15.0+ds1-2+deb11u2 |
| openvswitch | openvswitch | >= 0 < 3.1.0~git20221212.739bcf2-4 | 3.1.0~git20221212.739bcf2-4 |
| openvswitch | openvswitch | >= 0 < 3.1.0~git20221212.739bcf2-4 | 3.1.0~git20221212.739bcf2-4 |
| openvswitch | openvswitch | >= 0 < 3.1.0~git20221212.739bcf2-4 | 3.1.0~git20221212.739bcf2-4 |
| openvswitch | openvswitch | >= 2.14.0 < 2.14.8 | 2.14.8 |
| openvswitch | openvswitch | >= 2.15.0 < 2.15.7 | 2.15.7 |
| openvswitch | openvswitch | >= 2.16.0 < 2.16.6 | 2.16.6 |
| openvswitch | openvswitch | >= 2.17.0 < 2.17.5 | 2.17.5 |
| openvswitch | openvswitch | >= 3.0.0 < 3.0.3 | 3.0.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3ch9-x7v9-qhxv: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch
ghsa_unreviewed·2023-01-11
CVE-2022-4337 [CRITICAL] CWE-125 GHSA-3ch9-x7v9-qhxv: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
OSV
CVE-2022-4337: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch
osv·2023-01-10·CVSS 9.8
CVE-2022-4337 [CRITICAL] CVE-2022-4337: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2023-02-27
CVE-2022-4338 Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
Qian Chen discovered that Open vSwitch incorrectly handled certain
Organization Specific TLVs. A remote attacker could use this issue to cause
Open vSwitch to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
vendor_msrc·2023-01-10·CVSS 9.8
CVE-2022-4337 [CRITICAL] CWE-125 An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL
Red Hat
openvswitch: Out-of-Bounds Read in Organization Specific TLV
vendor_redhat·2022-12-20·CVSS 9.8
CVE-2022-4337 [CRITICAL] CWE-125 openvswitch: Out-of-Bounds Read in Organization Specific TLV
openvswitch: Out-of-Bounds Read in Organization Specific TLV
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
A flaw was found in the OpenvSwitch package. If LLDP processing is enabled for a specific port, crafted LLDP packets could cause a denial of service.
Statement: To exploit this vulnerability, it requires LLDP processing to be enabled for a specific port, which is unlikely to be exploitable in any of the Red Hat products. Considering this restriction, the impact is lowered to moderate.
Package: openvswitch (Fast Datapath for RHEL 7) - Out of support scope
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Affected
Package: openvswitch2.11 (Fast Datapath for RHEL 7) - Out of support scope
Package: openvswitch2.12 (Fast Datapat
Debian
CVE-2022-4337: openvswitch - An out-of-bounds read in Organization Specific TLV was found in various versions...
vendor_debian·2022·CVSS 9.8
CVE-2022-4337 [CRITICAL] CVE-2022-4337: openvswitch - An out-of-bounds read in Organization Specific TLV was found in various versions...
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Scope: local
bookworm: resolved (fixed in 3.1.0~git20221212.739bcf2-4)
bullseye: resolved (fixed in 2.15.0+ds1-2+deb11u2)
forky: resolved (fixed in 3.1.0~git20221212.739bcf2-4)
sid: resolved (fixed in 3.1.0~git20221212.739bcf2-4)
trixie: resolved (fixed in 3.1.0~git20221212.739bcf2-4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openvswitch/ovs/pull/405https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.htmlhttps://security.gentoo.org/glsa/202311-16https://www.debian.org/security/2023/dsa-5319https://www.openwall.com/lists/oss-security/2022/12/21/4https://github.com/openvswitch/ovs/pull/405https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.htmlhttps://security.gentoo.org/glsa/202311-16https://www.debian.org/security/2023/dsa-5319https://www.openwall.com/lists/oss-security/2022/12/21/4
2023-01-10
Published