CVE-2018-17206: Canonical Ubuntu Linux

Medium severity, CVSS 4.9. EPSS: 2% chance of exploitation in the next 30 days.

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 9.0 only
  • Openvswitch Openvswitch: from 2.7.0, up to and including 2.7.6
  • Red Hat Openstack: version 10 only; version 13 only

Published 2018-09-19. Last modified 2026-06-17.