#VU70471 Out-of-bounds read in Open vSwitch - CVE-2022-4337
Published: December 21, 2022
Open vSwitch
openvswitch.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when parsing Auto Attach TLV. A remote attacker can send specially crafted LLDP messages to the affected system, trigger an out-of-bounds read error and read contents of memory on the system of perform a denial of service (DoS) attack.