View at Official ubuntu advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2017-9214 medium priority: Ubuntu including 1 source packages (openvswitch), 5 status rows across 5 suites (trusty, upstream, xenial, yakkety, zesty): released 2, DNE 1, ignored 1, needs-triage 1.
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.