CVE-2020-27827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
18/03/2021
Last modified:
26/11/2023

Description

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:* 1.0.8 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.9 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.12 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.10 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.8 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.10.0 (including) 2.10.6 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.11.0 (including) 2.11.5 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.12.0 (including) 2.12.2 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.13.0 (including) 2.13.2 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.14.0 (including) 2.14.1 (excluding)
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*