CVE-2022-32166

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:cloudbase:open_vswitch:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:05

Type Values Removed Values Added
References () https://github.com/cloudbase/ovs/commit/2ed6505555cdcb46f9b1f0329d1491b75290fc73 - Patch, Third Party Advisory () https://github.com/cloudbase/ovs/commit/2ed6505555cdcb46f9b1f0329d1491b75290fc73 - Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2022/10/msg00036.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2022/10/msg00036.html - Mailing List, Third Party Advisory
References () https://www.mend.io/vulnerability-database/CVE-2022-32166 - Third Party Advisory () https://www.mend.io/vulnerability-database/CVE-2022-32166 - Third Party Advisory

07 Nov 2023, 03:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown

Information

Published : 2022-09-28 10:15

Updated : 2024-11-21 07:05


NVD link : CVE-2022-32166

Mitre link : CVE-2022-32166

CVE.ORG link : CVE-2022-32166


JSON object : View

Products Affected

debian

  • debian_linux

cloudbase

  • open_vswitch
CWE
CWE-125

Out-of-bounds Read