First published: Mon Oct 02 2017(Updated: )
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open vSwitch | <=2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14970 has a medium severity due to potential memory leaks affecting Open vSwitch versions prior to 2.8.1.
To remediate CVE-2017-14970, upgrade Open vSwitch to version 2.8.1 or later.
CVE-2017-14970 is caused by multiple memory leaks during the parsing of malformed OpenFlow group mod messages.
Open vSwitch versions prior to 2.8.1 are affected by CVE-2017-14970.
There is no official workaround for CVE-2017-14970; upgrading to a fixed version is the recommended approach.