CVE-2018-17206: Medium severity Openvswitch OpenvSwitch vulnerability
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decodebundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openvswitchto a version that resolves this vulnerability.Fixed in 2.15.0+ds1-2+deb11u5Fixed in 3.1.0-2+deb12u1Fixed in 3.5.0-1Fixed in 3.7.1-3
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-17206.
What is the severity of CVE-2018-17206?
The severity of CVE-2018-17206 is medium (4.9).
What is affected by CVE-2018-17206?
Open vSwitch (OvS) versions 2.7.x through 2.7.6 are affected by CVE-2018-17206.
How can I fix the vulnerability CVE-2018-17206?
To fix the vulnerability CVE-2018-17206, update Open vSwitch to version 2.10.7+ds1-0+deb10u1 or later.
Where can I find more information about CVE-2018-17206?
More information about CVE-2018-17206 can be found on the following links: [Link 1](https://access.redhat.com/errata/RHSA-2018:3500), [Link 2](https://access.redhat.com/errata/RHSA-2019:0053), [Link 3](https://access.redhat.com/errata/RHSA-2019:0081).