REDHAT-BUG-1457327: Medium severity open vswitch vulnerability
In Open vSwitch while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function ofpprintrolestatusmessage in lib/ofp-print.c that may be leveraged toward a remote DoS attack by a malicious switch.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332966.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1457327?
The severity of REDHAT-BUG-1457327 is classified as a potential remote denial of service (DoS) vulnerability.
How do I fix REDHAT-BUG-1457327?
To fix REDHAT-BUG-1457327, you should update to the latest version of Open vSwitch that addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-1457327?
The potential impacts of REDHAT-BUG-1457327 include disruption of service due to a remote DoS attack.
Who is affected by REDHAT-BUG-1457327?
Users and systems running vulnerable versions of Open vSwitch are affected by REDHAT-BUG-1457327.
What is the nature of the vulnerability in REDHAT-BUG-1457327?
The nature of the vulnerability in REDHAT-BUG-1457327 involves the abort() function being called due to undefined role status reasons, which can lead to a DoS condition.