9.8
CVSSv3

CVE-2017-9264

Published: 29/05/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openvswitch openvswitch 2.6.1

Vendor Advisories

Synopsis Moderate: openvswitch security update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Red Hat OpenStack Platform 110 (Ocata)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Several security issues were fixed in Open vSwitch ...
Debian Bug report logs - #863228 openvswtich: CVE-2017-9214 Package: openvswitch; Maintainer for openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 24 May 2017 05:51:01 UTC Severity: important Tags: patch, security, upstream Found in ...
Debian Bug report logs - #863661 openvswitch: CVE-2017-9264 Package: src:openvswitch; Maintainer for src:openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 May 2017 20:15:54 UTC Severity: normal Tags: patch, security, upstream Foun ...
Debian Bug report logs - #877543 CVE-2017-14970 Package: src:openvswitch; Maintainer for src:openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 2 Oct 2017 17:21:01 UTC Severity: important Tags: security, upstream Found in version openvswi ...
Debian Bug report logs - #863655 openvswitch: CVE-2017-9263 Package: src:openvswitch; Maintainer for src:openvswitch is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 May 2017 19:48:01 UTC Severity: normal Tags: patch, security, upstream Foun ...
A buffer over-read was found in the Open vSwitch (OvS) firewall implementation This flaw can be triggered by parsing a specially crafted TCP, UDP, or IPv6 packet A remote attack could use this flaw to cause a Denial of Service (DoS) ...