Assertion failure in Open vSwitch - CVE-2018-17204

 

Assertion failure in Open vSwitch - CVE-2018-17204

Published: December 16, 2018 / Updated: December 18, 2018


Vulnerability identifier: #VU16578
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17204
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in parse_group_prop_ntr_selection_method in lib/ofp-util.c due to validation of the group type and command after the whole group mod has been decoded. A remote attacker can trigger an an assertion failure via OVS_NOT_REACHED when the OF1.5 decoder tries to use the type and command earlier, when it might still be invalid.


Affected software

Open vSwitch
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization Host
Red Hat Virtualization Manager
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
openvswitch
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Fedora
Opensuse

How to mitigate CVE-2018-17204

Install update from vendor's website.

redhat-release-virtualization-host (Red Hat package) - update to 4.2-7.5.el7
redhat-virtualization-host (Red Hat package) - update to 4.2-20181121.0.el7_6
openvswitch - update to 2.10.0-1.fc29

External References

Related Security Bulletins