VDB
CVE-2022-32166
CVE-2022-32166
PUBLISHED
CVSS 8.800000190734863 HIGH
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
EPSS 0.61% · 46.9th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.61%
46.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cloudbase | open_vswitch | 0.90.0 |
| debian | debian_linux | 10.0 |
| ovs | ovs | unspecified, 0.90.0 |
Timeline
- Sep 28, 2022 CVE Published
- Sep 29, 2022 EPSS Score
- Oct 30, 2022 EPSS Score
- Nov 13, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 28, 2023 EPSS Score
- May 12, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
- Aug 10, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
- Dec 23, 2023 EPSS Score