An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2018:3500 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:0053 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:0081 | Third Party Advisory |
https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html | Mailing List Third Party Advisory |
https://usn.ubuntu.com/3873-1/ | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2018:3500 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:0053 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:0081 | Third Party Advisory |
https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html | Mailing List Third Party Advisory |
https://usn.ubuntu.com/3873-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 03:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/errata/RHSA-2018:3500 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:0053 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:0081 - Third Party Advisory | |
References | () https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html - Mailing List, Third Party Advisory | |
References | () https://usn.ubuntu.com/3873-1/ - Third Party Advisory |
Information
Published : 2018-09-19 16:29
Updated : 2024-11-21 03:54
NVD link : CVE-2018-17204
Mitre link : CVE-2018-17204
CVE.ORG link : CVE-2018-17204
JSON object : View
Products Affected
canonical
- ubuntu_linux
redhat
- openstack
debian
- debian_linux
openvswitch
- openvswitch
CWE
CWE-617
Reachable Assertion