cbcvebase.
CVE-2022-4338
published 2023-01-10

CVE-2022-4338: An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenvswitch< openvswitch 3.1.0~git20221212.739bcf2-4 (bookworm)openvswitch 3.1.0~git20221212.739bcf2-4 (bookworm)
msrccbl2_openvswitch_2.17.5-1_on_cbl_mariner_2.0
msrccm1_openvswitch_2.15.7-1_on_cbl_mariner_1.0
openvswitchopenvswitch< 2.13.102.13.10
openvswitchopenvswitch
openvswitchopenvswitch>= 0 < 2.15.0+ds1-2+deb11u22.15.0+ds1-2+deb11u2
openvswitchopenvswitch>= 0 < 3.1.0~git20221212.739bcf2-43.1.0~git20221212.739bcf2-4
openvswitchopenvswitch>= 0 < 3.1.0~git20221212.739bcf2-43.1.0~git20221212.739bcf2-4
openvswitchopenvswitch>= 0 < 3.1.0~git20221212.739bcf2-43.1.0~git20221212.739bcf2-4
openvswitchopenvswitch>= 2.14.0 < 2.14.82.14.8
openvswitchopenvswitch>= 2.15.0 < 2.15.72.15.7
openvswitchopenvswitch>= 2.16.0 < 2.16.62.16.6
openvswitchopenvswitch>= 2.17.0 < 2.17.52.17.5
openvswitchopenvswitch>= 3.0.0 < 3.0.33.0.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL