CVE-2016-2074: Openvswitch

Critical severity, CVSS 9.8. EPSS: 6.4% chance of exploitation in the next 30 days.

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.

Affected products

  • Openvswitch Openvswitch: version 2.2.0 only; version 2.3.0 only; version 2.3.1 only; version 2.3.2 only; version 2.4.0 only
  • Red Hat Openshift: version 3.1 only

Published 2016-07-03. Last modified 2026-06-17.