CVE-2017-14970: Medium severity Openvswitch OpenvSwitch vulnerability
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14970?
CVE-2017-14970 has a medium severity due to potential memory leaks affecting Open vSwitch versions prior to 2.8.1.
How do I fix CVE-2017-14970?
To remediate CVE-2017-14970, upgrade Open vSwitch to version 2.8.1 or later.
What causes CVE-2017-14970?
CVE-2017-14970 is caused by multiple memory leaks during the parsing of malformed OpenFlow group mod messages.
Which versions of Open vSwitch are affected by CVE-2017-14970?
Open vSwitch versions prior to 2.8.1 are affected by CVE-2017-14970.
Is there a workaround for CVE-2017-14970?
There is no official workaround for CVE-2017-14970; upgrading to a fixed version is the recommended approach.