Back to Database
Status published
Medium
CVE-2018-17206
An issue was discovered in Open vSwitch (OvS) 2.7.x through...
Vulnerability Description
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-17206
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2019:0053
- https://usn.ubuntu.com/3873-1/
- https://access.redhat.com/errata/RHSA-2018:3500
- https://github.com/openvswitch/ovs/commit/9237a63c47bd314b807cda0bd2216264e82edbe8
- https://access.redhat.com/errata/RHSA-2019:0081
- https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html
More from openvswitch
View All →CVE-2021-36980
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free...
Unknown
0
CVE-2019-25076
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x...
Medium
5.8
CVE-2018-17205
An issue was discovered in Open vSwitch (OvS) 2.7.x through...
High
7.5
CVE-2018-17204
An issue was discovered in Open vSwitch (OvS) 2.7.x through...
Medium
4.3
CVE-2017-9265
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read...
Critical
9.8
Affected Vendor
openvswitch
View all reports →Affected Software
openvswitch, openstack, ubuntu linux, debian linux
Vulnerable Versions:
2.7.0, 10, 13, 16.04, 18.04, 9.0
Timeline
Official Publish:
September 19th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.