Open vSwitch is a widely embedded virtual networking software that sits in the datapath of cloud infrastructure, container platforms, and virtualized environments across numerous deployments, yet maintains a focused single-product portfolio. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and resource-handling demands of a packet-processing codebase. The exposure recurs through weakness classes including out-of-bounds reads, uncontrolled resource consumption, buffer-boundary violations, and integer underflow conditions that are characteristic of low-level networking software. Defenders should treat this vendor's security updates as high-priority in any virtualized or containerized infrastructure where Open vSwitch handles packet forwarding. Current severity, exploitation activity, and exposure breadth are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openvswitch over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2074CRITICAL Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS | Jul 3, 2016 | 9.8 | 34 | NO | NO |
CVE-2022-4338CRITICAL An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. | Jan 10, 2023 | 9.8 | 32 | NO | NO |
CVE-2022-4337CRITICAL An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. | Jan 10, 2023 | 9.8 | 32 | NO | NO |
CVE-2017-9214CRITICAL In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the f | May 23, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-9265CRITICAL In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_of | May 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-9264CRITICAL In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extr | May 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-35498HIGH A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the r | Feb 11, 2021 | 7.5 | 27 | NO | NO |
CVE-2016-10377HIGH In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the functi | May 29, 2017 | 8.8 | 27 | NO | NO |
CVE-2023-3966HIGH A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering t | Feb 22, 2024 | 7.5 | 25 | NO | NO |
CVE-2021-3905HIGH A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sendi | Aug 23, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openvswitch.
Media articles that mention a CVE ID that affects a product developed by Openvswitch — matched by CVE ID, not by vendor name.