Integer underflow in Red Hat OpenStack - CVE-2017-9214

 

Integer underflow in Red Hat OpenStack - CVE-2017-9214

Published: September 14, 2017


Vulnerability identifier: #VU8433
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9214
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the Open vSwitch (OvS) component due to unsigned integer underflow in the function ofputil_pull_queue_get_config_reply10 in lib/ofp-util.c. when parsing of OFPT_QUEUE_GET_CONFIG_REPLY messages. A remote attacker can send a specially crafted OFPT_QUEUE_GET_CONFIG_REPLY message, trigger buffer over-read and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Red Hat OpenStack
Red Hat Virtualization
Red Hat Enterprise Linux Fast Datapath
Ubuntu
Fedora
openvswitch (Red Hat package)
openvswitch

How to mitigate CVE-2017-9214

Install update from vendor's website.

Red Hat OpenStack - addressed in versions 10.0, 11.0
openvswitch (Red Hat package) - addressed in versions 2.4.1-2.git20160727.el7ost, 2.6.1-13.git20161206.el7ost, 2.7.2-1.git20170719.el7fdp
openvswitch - addressed in versions 2.7.0-4.fc26, 2.7.0-5.fc26

External References

Related Security Bulletins