CVE-2024-22563
Published: 19 January 2024
openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
Notes
Author | Note |
---|---|
Priority reason: Denial of service due to memory leak. |
|
sbeattie | introduced in b6e840a ("pcap-file: Add nanosecond resolution pcap support.") (v2.11.0) |
mdeslaur | This is fixed in 2.17.0, the CVE description is wrong |
Priority
Status
Package | Release | Status |
---|---|---|
openvswitch Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Released
(2.13.8-0ubuntu1.1)
|
|
jammy |
Not vulnerable
|
|
lunar |
Not vulnerable
|
|
mantic |
Not vulnerable
|
|
noble |
Not vulnerable
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(2.13.5,2.17.0)
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://github.com/openvswitch/ovs/commit/3168f328c78cf6e4b3022940452673b0e49f7620 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |