CVE-2017-9265: Critical severity Openvswitch OpenvSwitch vulnerability
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in lib/ofp-util.c in the function ofputilpullofp15groupmod.
Other sources
In Open vSwitch there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in lib/ofp-util.c in the function ofputilpullofp15groupmod.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332965.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9265?
CVE-2017-9265 has been classified as a medium severity vulnerability due to the potential for buffer over-reads.
How do I fix CVE-2017-9265?
To mitigate CVE-2017-9265, upgrade Open vSwitch to version 2.7.1 or later where the vulnerability has been addressed.
What systems are affected by CVE-2017-9265?
CVE-2017-9265 specifically affects Open vSwitch version 2.7.0.
What kind of vulnerability is CVE-2017-9265?
CVE-2017-9265 is a buffer over-read vulnerability occurring in the parsing of OpenFlow messages within Open vSwitch.
Is CVE-2017-9265 exploitable remotely?
CVE-2017-9265 may potentially be exploited remotely depending on the configuration and access controls of the Open vSwitch installation.