=========================================================================Ubuntu Security Notice USN-5242-1
January 20, 2022

openvswitch vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10

Summary:

Open vSwitch could be made to hang or crash if it received specially
crafted network traffic.

Software Description:
- openvswitch: Ethernet virtual switch

Details:

It was discovered that Open vSwitch incorrectly handled certain fragmented
packets. A remote attacker could possibly use this issue to cause Open
vSwitch to consume resources, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
  openvswitch-common              2.16.0-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5242-1
  CVE-2021-3905

Package Information:
  https://launchpad.net/ubuntu/+source/openvswitch/2.16.0-0ubuntu2.1

Ubuntu 5242-1: Open vSwitch vulnerability

January 20, 2022
Open vSwitch could be made to hang or crash if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: openvswitch-common 2.16.0-0ubuntu2.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5242-1

CVE-2021-3905

Severity
January 20, 2022

Package Information

https://launchpad.net/ubuntu/+source/openvswitch/2.16.0-0ubuntu2.1

Related News