Assertion failure in Open vSwitch - CVE-2018-17205
Published: December 18, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in ofproto_rule_insert__ in ofproto/ofproto.c due to flows that are added in a bundle are applied to ofproto in order during bundle commit. A remote attacker can trigger an an assertion failure due to a check on rule state != RULE_INITIALIZED while reinserting old flows and cause the service to crash.
Affected software
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization Manager
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Fedora
Opensuse
openvswitch