Back

HIGH

ovs - buffer over-read

Published Sep 28, 2022

Description

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

Affected products

Remediation

Vendor solution

Update version to v2.5.1 or later

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mend
Published Sep 28, 2022
Updated May 21, 2025
Reserved May 31, 2022
CISA Vulnrichment
Updated May 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 28, 2022