CVE-2017-14970
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/10/2017
Last modified:
20/04/2025
Description
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* | 2.8.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



