Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
2016-07-03T21:59:10.837
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openvswitch | openvswitch | 2.2.0 | Yes |
| Application | openvswitch | openvswitch | 2.3.0 | Yes |
| Application | openvswitch | openvswitch | 2.3.1 | Yes |
| Application | openvswitch | openvswitch | 2.3.2 | Yes |
| Application | openvswitch | openvswitch | 2.4.0 | Yes |
| Application | redhat | openshift | 3.1 | Yes |