• 公告ID (KylinSec-SA-2022-2506)

摘要:

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

安全等级: Low

公告ID: KylinSec-SA-2022-2506

发布日期: 2022年10月21日

关联CVE: CVE-2022-32166  

  • 详细介绍

1. 漏洞描述

   

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-32166 KY3.4-4A python-openvswitch Unaffected
CVE-2022-32166 KY3.4-5A python-openvswitch Unaffected
CVE-2022-32166 KY3.5.1 python-openvswitch Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-2505 下一篇:KylinSec-SA-2022-2507