In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions extract_l3_ipv6, extract_l4_tcp, and extract_l4_udp that can be triggered remotely.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.1"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:openvswitch:openvswitch:2.6.1:*:*:*:*:*:*:*"
}