SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-32166

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c.

MEDIUM 6.1EPSS 0.58%

Does this matter?

Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.

Description

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
EPSS
0.58% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
cloudbase/open vswitch · debian/debian linux
Source
vulnerabilitylab@mend.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.