An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openvswitch-ovn-centralUpgrade python-openvswitchUpgrade openvswitch-ovn-hostUpgrade openvswitchUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-vtepUpgrade openvswitch-debuginfoUpgrade openvswitch-testUpgrade openvswitch-devel | Aug 28, 2019 | Sep 19, 2018 |
| Debian | — | Upgrade openvswitch | Feb 22, 2021 | Sep 19, 2018 |
| Redhat_linux | — | Upgrade openvswitch-develUpgrade openvswitchUpgrade openvswitch-ovn-centralUpgrade python-openvswitchUpgrade openvswitch-debuginfoUpgrade openvswitch-ovn-commonUpgrade openvswitch-testUpgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-host | Nov 6, 2018 | Sep 19, 2018 |
| Suse | — | Upgrade openvswitch | Dec 15, 2018 | Sep 19, 2018 |
| Ubuntu | — | Upgrade openvswitch-common | Feb 5, 2019 | Sep 19, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub