An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-hostUpgrade openvswitch-testUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-centralUpgrade python-openvswitchUpgrade openvswitchUpgrade openvswitch-debuginfoUpgrade openvswitch-devel | Aug 28, 2019 | Sep 19, 2018 |
| Debian | — | Upgrade openvswitch | Feb 22, 2021 | Sep 19, 2018 |
| Redhat_linux | — | Upgrade openvswitch-testUpgrade openvswitch-ovn-centralUpgrade openvswitch-develUpgrade openvswitchUpgrade openvswitch-ovn-vtepUpgrade python-openvswitchUpgrade openvswitch-debuginfoUpgrade openvswitch-ovn-hostUpgrade openvswitch-ovn-common | Nov 6, 2018 | Sep 19, 2018 |
| Suse | — | Upgrade openvswitch | Dec 15, 2018 | Sep 19, 2018 |
| Ubuntu | — | Upgrade openvswitch-common | Feb 5, 2019 | Sep 19, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub