CVE-2022-4338

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

26 Nov 2023, 11:15

Type Values Removed Values Added
References
  • () https://security.gentoo.org/glsa/202311-16 -

18 Jan 2023, 20:26

Type Values Removed Values Added
First Time Debian
Debian debian Linux
References (DEBIAN) https://www.debian.org/security/2023/dsa-5319 - (DEBIAN) https://www.debian.org/security/2023/dsa-5319 - Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

14 Jan 2023, 08:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2023/dsa-5319 -
CWE CWE-191 CWE-125

14 Jan 2023, 04:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-125 CWE-191
First Time Openvswitch openvswitch
Openvswitch
CPE cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
References (MISC) https://www.openwall.com/lists/oss-security/2022/12/21/4 - (MISC) https://www.openwall.com/lists/oss-security/2022/12/21/4 - Mailing List, Third Party Advisory
References (MISC) https://github.com/openvswitch/ovs/pull/405 - (MISC) https://github.com/openvswitch/ovs/pull/405 - Patch, Third Party Advisory
References (MISC) https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html - (MISC) https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html - Mailing List, Patch, Vendor Advisory

10 Jan 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-10 22:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-4338

Mitre link : CVE-2022-4338

CVE.ORG link : CVE-2022-4338


JSON object : View

Products Affected

debian

  • debian_linux

openvswitch

  • openvswitch
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)