4
CVSSv2

CVE-2018-17204

Published: 19/09/2018 Updated: 04/08/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Open vSwitch (OvS) 2.7.x up to and including 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command previous versions, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openvswitch openvswitch

redhat openstack 10

redhat openstack 13

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in Open vSwitch ...
Synopsis Moderate: openvswitch security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis Moderate: openvswitch security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis Moderate: openvswitch security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Commo ...
An issue was discovered in Open vSwitch (OvS), 24x through 241, 25x through 255, 26x through 263, 27x through 276, 28x through 284, and29x through 292, affecting the parse_group_prop_ntr_selection_method in lib/ofp-utilc On controllers with the OpenFlow 15 decoder enabled, a specially crafted group update can cause an ass ...