REDHAT-BUG-1632528: Medium severity Open vSwitch Open vSwitch vulnerability
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decodebundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Upstream Patch:
https://nvd.nist.gov/vuln/detail/CVE-2018-17206
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open vSwitchto a version that resolves this vulnerability.Patch CVE-2018-17206 - Operational
Identify all deployments running Open vSwitch 2.7.x through 2.7.6 and apply the upstream patch referenced by CVE-2018-17206.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1632528?
The severity of REDHAT-BUG-1632528 is considered moderate due to its potential for buffer over-read issues.
How do I fix REDHAT-BUG-1632528?
To fix REDHAT-BUG-1632528, update Open vSwitch to a version later than 2.7.6 where the vulnerability has been patched.
What versions of Open vSwitch are affected by REDHAT-BUG-1632528?
Open vSwitch versions 2.7.x through 2.7.6 are affected by REDHAT-BUG-1632528.
What is the nature of the vulnerability in REDHAT-BUG-1632528?
REDHAT-BUG-1632528 pertains to a buffer over-read issue during the decoding of BUNDLE actions in Open vSwitch.
Where can I find more information about REDHAT-BUG-1632528?
Additional information about REDHAT-BUG-1632528 can be found in the Red Hat bug report and related security advisories.