An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-openvswitchUpgrade openvswitch-ovn-hostUpgrade openvswitch-ovn-centralUpgrade openvswitch-develUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-vtepUpgrade openvswitch-testUpgrade openvswitchUpgrade openvswitch-debuginfo | Aug 28, 2019 | Sep 19, 2018 |
| Debian | — | Upgrade openvswitch | Feb 22, 2021 | Sep 19, 2018 |
| Redhat_linux | — | Upgrade openvswitch-develUpgrade openvswitch-ovn-centralUpgrade openvswitchUpgrade openvswitch-ovn-vtepUpgrade openvswitch-testUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-hostUpgrade openvswitch-debuginfoUpgrade python-openvswitch | Nov 6, 2018 | Sep 19, 2018 |
| Suse | — | Upgrade openvswitch | Dec 15, 2018 | Sep 19, 2018 |
| Ubuntu | — | Upgrade openvswitch-common | Feb 5, 2019 | Sep 19, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub