Lucene search

K
redhatcveRedhat.comRH:CVE-2018-17206
HistoryApr 02, 2020 - 8:18 a.m.

CVE-2018-17206

2020-04-0208:18:46
redhat.com
access.redhat.com
13

EPSS

0.003

Percentile

69.7%

An issue was discovered in Open vSwitch (OvS) 2.5.x through 2.5.5, 2.6.x through 2.6.3, 2.7.x through 2.7.6, 2.8.x through 2.8.4, and 2.9.x through 2.9.2 where the decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding. A specially crafted flow update applied using the bundling feature of Open vSwitch could potentially cause a crash leading to a denial of service.