CVE-2017-14970

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/10/2017
Last modified:
20/04/2025

Description

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.8.0 (including)