In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openvswitch | Oct 31, 2022 | Sep 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 28, 2022 |
| Suse | — | Upgrade libopenvswitch-2_8-0Upgrade openvswitch-ovn-dockerUpgrade openvswitch-ovn-hostUpgrade libdpdk-18_11Upgrade openvswitchUpgrade openvswitch-dpdk-switchUpgrade openvswitch-ovn-vtepUpgrade openvswitch-dpdkUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-centralUpgrade openvswitch-switchUpgrade libopenvswitch-2_11-0 | Nov 18, 2022 | Sep 28, 2022 |
| Ubuntu | — | Upgrade openvswitch-commonUpgrade openvswitch-common (Ubuntu Pro) | Oct 25, 2022 | Sep 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub