CVE Tools

Openvswitch

9 CVEs tracked since 2016. Since Jul 2016, none of them reached CISA KEV.

Openvswitch CVEs per month

Jul 2016 to Sep 2018. Point at a month, or focus the strip and use the arrow keys.
Openvswitch CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0710
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-0550
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-0930

Products

The products that kept showing up in Openvswitch's monthly top three, with their CVEs summed over those months.

  1. Openvswitch93 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Openvswitch.

  1. CVE-2023-3966Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet7.5
  2. CVE-2024-22563openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.7.5
  3. CVE-2023-5366Openvswitch don't match packets on nd_target field7.1
  4. CVE-2022-4338An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.9.8
  5. CVE-2022-4337An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.9.8
  6. CVE-2019-25076The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that ...5.8
  7. CVE-2022-0669A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages ...6.5
  8. CVE-2021-3905A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.7.5
  9. CVE-2021-36980Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.5.5
  10. CVE-2020-27827A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial ...7.5
  11. CVE-2020-35498A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow...7.5
  12. CVE-2018-17206An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.4.9
  13. CVE-2018-17205An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofprot...7.5
  14. CVE-2018-17204An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and comm...4.3
  15. CVE-2017-14970In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, st...5.9

The record

Peak rank
#73 in May 2017
Busiest month shown
May 2017, 5 CVEs
Months with a KEV entry
0 since Jul 2016
Monthly snapshots
3 since 2016
Openvswitch's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store