VDB

CVE-2022-32166

CVE-2022-32166 PUBLISHED CVSS 8.800000190734863 HIGH

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

EPSS 1.66% · 82.4th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.66%
82.4th percentile

Affected Products

VendorProductVersions
cloudbaseopen_vswitch0.90.0
debiandebian_linux10.0
ovsovsunspecified, 0.90.0

Timeline

  • Sep 28, 2022 CVE Published
  • Sep 29, 2022 EPSS Score
  • Oct 30, 2022 EPSS Score
  • Nov 12, 2022 EPSS Score
  • Dec 27, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 26, 2023 EPSS Score
  • May 9, 2023 EPSS Score
  • Jun 23, 2023 EPSS Score
  • Aug 6, 2023 EPSS Score
  • Sep 20, 2023 EPSS Score
  • Nov 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›