VYPR

Openvswitch

by Openvswitch

CVEs (28)

  • CVE-2022-4337CriJan 10, 2023
    risk 0.00cvss 9.8epss 0.01

    An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

  • CVE-2022-0669MedAug 29, 2022
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages…

  • CVE-2021-3905HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.02

    A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

  • CVE-2021-36980MedJul 20, 2021
    risk 0.00cvss 5.5epss 0.01

    Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

  • CVE-2018-17206MedSep 19, 2018
    risk 0.00cvss 4.9epss 0.02

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

  • CVE-2018-17205HigSep 19, 2018
    risk 0.00cvss 7.5epss 0.03

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a…

  • CVE-2018-17204MedSep 19, 2018
    risk 0.00cvss 4.3epss 0.02

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries…

  • CVE-2012-3449Aug 7, 2012
    risk 0.00cvss epss 0.00

    Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.

Page 2 of 2