cve/2019/CVE-2019-25076.md

19 lines
867 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-25076](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25076)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.
### POC
#### Reference
- https://www.youtube.com/watch?v=5cHpzVK0D28
- https://www.youtube.com/watch?v=DSC3m-Bww64
#### Github
- https://github.com/Live-Hack-CVE/CVE-2019-25076