CVE-2017-9264: Critical severity Openvswitch OpenvSwitch vulnerability
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions extractl3ipv6, extractl4tcp, and extractl4udp that can be triggered remotely.
Other sources
In lib/conntrack.c in the firewall implementation in Open vSwitch, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions extractl3ipv6, extractl4tcp, and extractl4udp that can be triggered remotely.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9264?
CVE-2017-9264 has been classified with a medium severity level due to the potential for remote exploitation through malformed packets.
What versions of Open vSwitch are affected by CVE-2017-9264?
CVE-2017-9264 affects Open vSwitch version 2.6.1.
How do I fix CVE-2017-9264?
To fix CVE-2017-9264, upgrade your Open vSwitch installation to a version that is not vulnerable.
What type of vulnerability is CVE-2017-9264?
CVE-2017-9264 is a buffer over-read vulnerability that occurs while parsing certain malformed network packets.
Can CVE-2017-9264 be exploited remotely?
Yes, CVE-2017-9264 can be exploited remotely by sending malformed TCP, UDP, or IPv6 packets.