PT-2022-8294 · Unknown+2 · Openvswitch+2

Published

2022-09-08

·

Updated

2023-10-22

·

CVE-2019-25076

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open vSwitch versions 2.x through 2.17.2 Open vSwitch version 3.0.0
Description The issue allows remote attackers to cause a denial of service, resulting in delays of legitimate traffic. This is achieved via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, also known as a Tuple Space Explosion (TSE) attack.
Recommendations For Open vSwitch versions 2.x through 2.17.2, update to a version later than 2.17.2 to resolve the issue. For Open vSwitch version 3.0.0, update to a version later than 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the MegaFlow cache to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

ALT-PU-2023-1745
ALT-PU-2023-1806
AZL-10905
CVE-2019-25076
ROSA-SA-2023-2262

Affected Products

Alt Linux
Debian
Openvswitch