Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1456795 - (CVE-2017-9214) CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_co...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170520,repor...
: Security
Depends On: 1456797 1455625 1466564 1466565 1466566 1466567 1466568 1466569 1466570 1470450 1470456 1471563
Blocks: 1456799
  Show dependency treegraph
 
Reported: 2017-05-30 07:48 EDT by Andrej Nemec
Modified: 2018-06-29 18:21 EDT (History)
43 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An unsigned integer wrap around that led to a buffer over-read was found when parsing OFPT_QUEUE_GET_CONFIG_REPLY messages in Open vSwitch (OvS). An attacker could use this issue to cause a remote denial of service attack.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:2418 normal SHIPPED_LIVE Moderate: openvswitch security, bug fix, and enhancement update 2017-08-03 12:35:07 EDT
Red Hat Product Errata RHSA-2017:2553 normal SHIPPED_LIVE Moderate: openvswitch security update 2017-08-30 13:59:59 EDT
Red Hat Product Errata RHSA-2017:2648 normal SHIPPED_LIVE Moderate: openvswitch security and bug fix update 2017-09-06 16:53:24 EDT
Red Hat Product Errata RHSA-2017:2665 normal SHIPPED_LIVE Moderate: openvswitch security update 2017-09-06 17:49:41 EDT
Red Hat Product Errata RHSA-2017:2692 normal SHIPPED_LIVE Moderate: openvswitch security update 2017-09-12 17:11:39 EDT
Red Hat Product Errata RHSA-2017:2698 normal SHIPPED_LIVE Moderate: openvswitch security update 2017-09-12 17:20:40 EDT
Red Hat Product Errata RHSA-2017:2727 normal SHIPPED_LIVE Moderate: openvswitch security update 2017-09-13 21:39:00 EDT

  None (edit)
Description Andrej Nemec 2017-05-30 07:48:39 EDT
A vulnerability in openvswitch was found. While parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.

References:

https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332711.html
Comment 1 Andrej Nemec 2017-05-30 07:49:24 EDT
Created openvswitch tracking bugs for this issue:

Affects: fedora-all [bug 1456797]
Comment 13 errata-xmlrpc 2017-08-03 08:36:49 EDT
This issue has been addressed in the following products:

  Fast Datapath for RHEL 7

Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
Comment 14 errata-xmlrpc 2017-08-30 10:06:00 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 9.0 (Mitaka)

Via RHSA-2017:2553 https://access.redhat.com/errata/RHSA-2017:2553
Comment 15 errata-xmlrpc 2017-09-06 13:02:19 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 10.0 (Newton)

Via RHSA-2017:2648 https://access.redhat.com/errata/RHSA-2017:2648
Comment 16 errata-xmlrpc 2017-09-06 13:51:35 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7

Via RHSA-2017:2665 https://access.redhat.com/errata/RHSA-2017:2665
Comment 17 errata-xmlrpc 2017-09-12 13:13:51 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 8.0 (Liberty)

Via RHSA-2017:2692 https://access.redhat.com/errata/RHSA-2017:2692
Comment 18 errata-xmlrpc 2017-09-12 13:22:27 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7

Via RHSA-2017:2698 https://access.redhat.com/errata/RHSA-2017:2698
Comment 19 errata-xmlrpc 2017-09-13 17:41:56 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 11.0 (Ocata)

Via RHSA-2017:2727 https://access.redhat.com/errata/RHSA-2017:2727
Comment 20 Jason Shepherd 2018-04-03 03:26:52 EDT
Updated fixed in version to 2.7.2-1 based on packages released in https://access.redhat.com/errata/RHSA-2017:2418.

Openshift Enterprise 3.7 uses the fixed version 2.7.2-1. Marking as not affected.

Note You need to log in before you can comment on or make changes to this bug.