cbcvebase.

Openvswitch vulnerabilities

25 known vulnerabilities affecting openvswitch/openvswitch.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH8MEDIUM9LOW1

Vulnerabilities

Page 1 of 2
CVE-2016-2074P3CRITICALCVSS 9.8v2.2.0v2.3.0+3 more2016-07-03
CVE-2016-2074 [CRITICAL] CWE-119 CVE-2016-2074: Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
nvdosv
CVE-2015-8011P3CRITICALCVSS 9.8≥ 0, < 2.15.0~git20210104.def6eb1ea+dfsg1-12020-01-28
CVE-2015-8011 [CRITICAL] CVE-2015-8011: Buffer overflow in the lldp_decode function in daemon/protocols/lldp Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
osv
CVE-2022-4338P3CRITICALCVSS 9.8fixed in 2.13.10≥ 2.14.0, < 2.14.8+5 more2023-01-10
CVE-2022-4338 [CRITICAL] CWE-125 CVE-2022-4338: An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
nvdosv
CVE-2020-35498P3HIGHCVSS 7.5≥ 2.5.0, < 2.5.12≥ 2.6.0, < 2.6.10+9 more2021-02-11
CVE-2020-35498 [HIGH] CWE-400 CVE-2020-35498: A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet par A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
nvdosv
CVE-2017-9264P3CRITICALCVSS 9.8v2.6.12017-05-29
CVE-2017-9264 [CRITICAL] CWE-125 CVE-2017-9264: In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer ove In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
nvdosv
CVE-2016-10377P3HIGHCVSS 8.8v2.5.02017-05-29
CVE-2016-10377 [HIGH] CWE-119 CVE-2016-10377: In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.
nvdosv
CVE-2023-1668P3HIGHCVSS 8.2≥ 0, < 2.15.0+ds1-2+deb11u4≥ 0, < 3.1.0-22023-04-10
CVE-2023-1668 [HIGH] CVE-2023-1668: A flaw was found in openvswitch (OVS) A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP proto
osv
CVE-2022-4337P3CRITICALCVSS 9.8fixed in 2.13.10≥ 2.14.0, < 2.14.8+5 more2023-01-10
CVE-2022-4337 [CRITICAL] CWE-125 CVE-2022-4337: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
nvdosv
CVE-2017-9214P3CRITICALCVSS 9.8v2.7.02017-05-23
CVE-2017-9214 [CRITICAL] CWE-191 CVE-2017-9214: In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, ther In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
nvdosv
CVE-2017-9265P3CRITICALCVSS 9.8v2.7.02017-05-29
CVE-2017-9265 [CRITICAL] CWE-125 CVE-2017-9265: In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow messa In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.
nvdosv
CVE-2020-27827P3HIGHCVSS 7.5≥ 2.6.0, < 2.6.9≥ 2.7.0, < 2.7.12+7 more2021-03-18
CVE-2020-27827 [HIGH] CWE-400 CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memor A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
nvdosv
CVE-2023-3966P3HIGHCVSS 7.5fixed in 3.1.02024-02-22
CVE-2023-3966 [HIGH] CWE-248 CVE-2023-3966: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, w A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
nvdosv
CVE-2021-3905P3HIGHCVSS 7.5fixed in 2.17.02022-08-23
CVE-2021-3905 [HIGH] CWE-401 CVE-2021-3905: A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attac A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
nvdosv
CVE-2018-17205P3HIGHCVSS 7.5≥ 2.7.0, ≤ 2.7.62018-09-19
CVE-2018-17205 [HIGH] CWE-617 CVE-2018-17205: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ i An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows tha
nvdosv
CVE-2024-22563P4HIGHCVSS 7.5v2.17.82024-01-19
CVE-2024-22563 [HIGH] CWE-401 CVE-2024-22563: openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
nvdosv
CVE-2023-5366P4MEDIUMCVSS 5.5fixed in 2023-02-282023-10-06
CVE-2023-5366 [MEDIUM] CWE-345 CVE-2023-5366: A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual m A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
nvdosv
CVE-2019-25076P4MEDIUMCVSS 5.8≥ 2.0.0, ≤ 2.17.2v3.0.02022-09-08
CVE-2019-25076 [MEDIUM] CVE-2019-25076: The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote at The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.
nvd
CVE-2022-32166P4MEDIUMCVSS 6.1≥ 0, < 2.13.0+dfsg1-12022-09-28
CVE-2022-32166 [MEDIUM] CVE-2022-32166: In ovs versions v0 In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
osv
CVE-2022-0669P4MEDIUMCVSS 6.5v2.13.0v2.15.02022-08-29
CVE-2022-0669 [MEDIUM] CWE-400 CVE-2022-0669: A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected num A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave proc
nvd
CVE-2017-14970P4MEDIUMCVSS 5.9≤ 2.8.02017-10-02
CVE-2017-14970 [MEDIUM] CWE-772 CVE-2017-14970: In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to alloca
nvdosv
Openvswitch vulnerabilities | cvebase