CVE-2017-9265: Openvswitch

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.

Affected products

Published 2017-05-29. Last modified 2026-06-17.