In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openvswitch | Oct 31, 2022 | Sep 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 28, 2022 |
| Suse | — | Upgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-centralUpgrade libopenvswitch-2_11-0Upgrade openvswitch-switchUpgrade openvswitch-dpdkUpgrade openvswitch-ovn-hostUpgrade libdpdk-18_11Upgrade openvswitch-dpdk-switchUpgrade openvswitch-ovn-dockerUpgrade libopenvswitch-2_8-0Upgrade openvswitch | Nov 18, 2022 | Sep 28, 2022 |
| Ubuntu | — | Upgrade openvswitch-commonUpgrade openvswitch-common (Ubuntu Pro) | Oct 25, 2022 | Sep 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub