Search CVE reports


Toggle filters

11 – 20 of 25 results


CVE-2020-35498

Medium priority
Fixed

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide,...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Fixed Fixed
Show less packages

CVE-2020-27827

Medium priority

Some fixes available 13 of 26

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat...

2 affected packages

openvswitch, lldpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Fixed Fixed Fixed Fixed
lldpd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-25076

Medium priority
Vulnerable

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-17206

Medium priority
Fixed

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Fixed
Show less packages

CVE-2018-17205

Medium priority
Fixed

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Fixed
Show less packages

CVE-2018-17204

Medium priority
Fixed

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch Fixed
Show less packages

CVE-2017-9265

Medium priority

Some fixes available 2 of 3

In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch
Show less packages

CVE-2017-9264

Medium priority

Some fixes available 1 of 2

In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`,...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch
Show less packages

CVE-2017-9263

Medium priority

Some fixes available 2 of 3

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch
Show less packages

CVE-2017-9214

Medium priority

Some fixes available 2 of 3

In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in...

1 affected package

openvswitch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvswitch
Show less packages