CVE-2022-32166: ovs - buffer over-read
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32166?
The severity of CVE-2022-32166 is high.
What is the affected software of CVE-2022-32166?
The affected software of CVE-2022-32166 includes Cloudbase Open Vswitch and Debian Debian Linux.
What is the vulnerability description of CVE-2022-32166?
CVE-2022-32166 is a heap buffer over-read vulnerability in ovs versions v0.90.0 through v2.5.0, which can lead to crashes, memory modification, and possible remote execution.
How can I fix CVE-2022-32166?
To fix CVE-2022-32166, update ovs to a version higher than v2.5.0.
Is there any additional information about CVE-2022-32166?
Yes, you can find more information about CVE-2022-32166 in the references provided: [1](https://github.com/cloudbase/ovs/commit/2ed6505555cdcb46f9b1f0329d1491b75290fc73), [2](https://lists.debian.org/debian-lts-announce/2022/10/msg00036.html), [3](https://www.mend.io/vulnerability-database/CVE-2022-32166).