AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-9264

CRITICAL · CVSS 9.8 EPSS 2.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-05-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-9264
Severity
CRITICAL
CVSS
9.8
EPSS
2.42%

Original NVD Description

In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.