{"id":"CVE-2016-10377","details":"In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.","modified":"2026-07-08T12:43:46.996521Z","published":"2017-05-29T04:29:00.243Z","references":[{"type":"FIX","url":"https://mail.openvswitch.org/pipermail/ovs-dev/2016-July/319503.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openvswitch/ovs","events":[{"introduced":"22d4614ddf83988a3771fb379ea029e663b4455a"},{"last_affected":"22d4614ddf83988a3771fb379ea029e663b4455a"}],"database_specific":{"cpe":"cpe:2.3:a:openvswitch:openvswitch:2.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.5.0"},{"last_affected":"2.5.0"}],"source":"CPE_STRING"}}],"versions":["2.5.0","v2.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10377.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}