CVE-2022-4337: Critical severity open vswitch vulnerability
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-4337?
CVE-2022-4337 is an out-of-bounds read vulnerability in Organization Specific TLV found in various versions of OpenvSwitch.
Which versions of OpenvSwitch are affected by CVE-2022-4337?
Versions up to and including 2.13.10, versions from 2.14.0 to 2.14.8, versions from 2.15.0 to 2.15.7, versions from 2.16.0 to 2.16.6, versions from 2.17.0 to 2.17.5, and versions from 3.0.0 to 3.0.3 of OpenvSwitch are affected by CVE-2022-4337.
What is the severity of CVE-2022-4337?
CVE-2022-4337 has a severity rating of 9.8 (critical).
How can I fix CVE-2022-4337 in OpenvSwitch?
To fix CVE-2022-4337 in OpenvSwitch, update to version 2.10.7+ds1-0+deb10u4, 2.15.0+ds1-2+deb11u4, 3.1.0-2, or 3.2.0-2 if using the Debian package.
Where can I find more information about CVE-2022-4337?
More information about CVE-2022-4337 can be found at the following references: [1](https://github.com/openvswitch/ovs/pull/405), [2](https://security-tracker.debian.org/tracker/CVE-2022-4337), [3](https://security-tracker.debian.org/tracker/CVE-2022-4338).