Buffer overflow in Open vSwitch - CVE-2016-2074
Published: April 2, 2018 / Updated: April 2, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in lib/flow.c in ovs-vswitchd due to boundary error. A remote attacker can send specially crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command, and execute arbitrary code.
Affected software
Debian Linux
Gentoo Linux
openvswitch (Alpine package)
openvswitch (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat OpenStack
How to mitigate CVE-2016-2074
openvswitch (Red Hat package) - update to 2.4.0-2.el7_2
External References
Related Security Bulletins
- Debian update for openvswitch
- Gentoo update for Open vSwitch
- Red Hat update for openvswitch
- Red Hat update for openvswitch
- Buffer overflow in openvswitch (Alpine package)
- Red Hat Enterprise Linux OpenStack Platform 6 update for openvswitch
- Red Hat Enterprise Linux OpenStack Platform 5 update for openvswitch