=========================================================================Ubuntu Security Notice USN-3873-1
January 30, 2019

openvswitch vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Open vSwitch.

Software Description:
- openvswitch: Ethernet virtual switch

Details:

It was discovered that Open vSwitch incorrectly decoded certain packets. A
remote attacker could possibly use this issue to cause Open vSwitch to
crash, resulting in a denial of service. (CVE-2018-17204)

It was discovered that Open vSwitch incorrectly handled processing certain
flows. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-17205)

It was discovered that Open vSwitch incorrectly handled BUNDLE action
decoding. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. (CVE-2018-17206)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  openvswitch-common              2.9.2-0ubuntu0.18.04.3

Ubuntu 16.04 LTS:
  openvswitch-common              2.5.5-0ubuntu0.16.04.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3873-1
  CVE-2018-17204, CVE-2018-17205, CVE-2018-17206

Package Information:
  https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3
  https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2

Ubuntu 3873-1: Open vSwitch vulnerabilities

January 30, 2019
Several security issues were fixed in Open vSwitch.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: openvswitch-common 2.9.2-0ubuntu0.18.04.3 Ubuntu 16.04 LTS: openvswitch-common 2.5.5-0ubuntu0.16.04.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3873-1

CVE-2018-17204, CVE-2018-17205, CVE-2018-17206

Severity
January 30, 2019

Package Information

https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3 https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2

Related News