ryu@4.34 vulnerabilities

Component-based Software-defined Networking Framework

Direct Vulnerabilities

Known vulnerabilities in the ryu package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop in the OFPPacketQueue() function in *parser.py. An attacker can cause denial of service by sending data with OFPQueueProp.len set to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop in the OFPFlowStats() function in *parser.py. An attacker can cause denial of service by sending data in which inst.length is set to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop in the OFPBucket() function in *parser.py. An attacker can cause denial of service by sending data in which action.len is set to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop due to the OFPMultipartReply in *parser.py. An attacker can cause a denial of service condition by setting b.length to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop via the OFPHello in *parser.py, by setting the length to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop due to the improper handling of OFPGroupDescStats in *parser.py. An attacker can trigger an infinite loop by setting OFPBucket.len to 0.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Infinite Loop

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Infinite Loop due to an issue in OFPMatch in *parser.py. An attacker can cause a denial of service.

How to fix Infinite Loop?

There is no fixed version for ryu.

[0,)
  • M
Allocation of Resources Without Limits or Throttling

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in OFPQueueGetConfigReply in parser.py.

How to fix Allocation of Resources Without Limits or Throttling?

There is no fixed version for ryu.

[0,)
  • M
Allocation of Resources Without Limits or Throttling

ryu is a Component-based Software-defined Networking Framework

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in OFPBundleCtrlMsg in parser.py, which allows a remote attacker to cause an infinite loop

How to fix Allocation of Resources Without Limits or Throttling?

There is no fixed version for ryu.

[0,)