CVE-2018-17206: Canonical Ubuntu Linux
Medium severity, CVSS 4.9. EPSS: 2% chance of exploitation in the next 30 days.
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 9.0 only
- Openvswitch Openvswitch: from 2.7.0, up to and including 2.7.6
- Red Hat Openstack: version 10 only; version 13 only
Published 2018-09-19. Last modified 2026-06-17.