Memory Leak Vulnerability in OpenvSwitch Affects System Availability
CVE-2020-27827

7.5HIGH

Key Information:

Vendor
CVE Published:
18 March 2021

What is CVE-2020-27827?

A vulnerability exists in specific versions of OpenvSwitch, where specially crafted LLDP packets can lead to memory allocation issues associated with optional TLVs. This flaw poses a risk of denial of service, significantly impacting system availability. Users of affected versions should take immediate action to update or mitigate risks associated with this vulnerability.

Affected Version(s)

lldp/openvswitch lldpd 1.0.8, openvswitch 2.14.1, openvswitch 2.13.2, openvswitch 2.12.2, openvswitch 2.11.5, openvswitch 2.10.6, openvswitch 2.9.8, openvswitch 2.8.10, openvswitch 2.7.12, openvswitch 2.6.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.