CVE-2022-4338: Integer Underflow
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-4338?
CVE-2022-4338 is an integer underflow vulnerability in Organization Specific TLV in various versions of OpenvSwitch.
Which versions of OpenvSwitch are affected by CVE-2022-4338?
Various versions of OpenvSwitch including 2.13.10 up to but excluding 2.14.8, 2.15.7 up to but excluding 2.16.6, 2.17.5 up to but excluding 3.0.3 are affected by CVE-2022-4338.
How severe is CVE-2022-4338?
CVE-2022-4338 has a severity score of 9.8, which is considered critical.
How can I fix CVE-2022-4338?
To fix CVE-2022-4338, you should update OpenvSwitch to version 2.10.7+ds1-0+deb10u4, 2.15.0+ds1-2+deb11u4, 3.1.0-2, or 3.2.0-2.
Where can I find more information about CVE-2022-4338?
You can find more information about CVE-2022-4338 in the following references: [GitHub Pull Request](https://github.com/openvswitch/ovs/pull/405), [OpenvSwitch Mailing List](https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html), [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5319).