CVE-2018-17204

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Configuration 4 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:54

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2018:3500 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2018:3500 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:0053 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:0053 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:0081 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:0081 - Third Party Advisory
References () https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde - Patch, Third Party Advisory () https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde - Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html - Mailing List, Third Party Advisory
References () https://usn.ubuntu.com/3873-1/ - Third Party Advisory () https://usn.ubuntu.com/3873-1/ - Third Party Advisory

Information

Published : 2018-09-19 16:29

Updated : 2024-11-21 03:54


NVD link : CVE-2018-17204

Mitre link : CVE-2018-17204

CVE.ORG link : CVE-2018-17204


JSON object : View

Products Affected

canonical

  • ubuntu_linux

redhat

  • openstack

debian

  • debian_linux

openvswitch

  • openvswitch
CWE
CWE-617

Reachable Assertion