An update for openvswitch2.13 is now available for Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openvswitch2.13 security update Advisory ID: RHSA-2023:1823-01 Product: Fast Datapath Advisory URL: https://access.redhat.com/errata/RHSA-2023:1823 Issue date: 2023-04-18 CVE Names: CVE-2023-1668 ==================================================================== 1. Summary: An update for openvswitch2.13 is now available for Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Fast Datapath for Red Hat Enterprise Linux 8 - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. Security Fix(es): * openvswitch: ip proto 0 triggers incorrect handling (CVE-2023-1668) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [23.C RHEL-8] Fast Datapath Release (BZ#2184495) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2137666 - CVE-2023-1668 openvswitch: ip proto 0 triggers incorrect handling 2184495 -[23.C RHEL-8] Fast Datapath Release 6. Package List: Fast Datapath for Red Hat Enterprise Linux 8: Source: openvswitch2.13-2.13.0-214.el8fdp.src.rpm aarch64: network-scripts-openvswitch2.13-2.13.0-214.el8fdp.aarch64.rpm openvswitch2.13-2.13.0-214.el8fdp.aarch64.rpm openvswitch2.13-debuginfo-2.13.0-214.el8fdp.aarch64.rpm openvswitch2.13-debugsource-2.13.0-214.el8fdp.aarch64.rpm openvswitch2.13-devel-2.13.0-214.el8fdp.aarch64.rpm openvswitch2.13-ipsec-2.13.0-214.el8fdp.aarch64.rpm python3-openvswitch2.13-2.13.0-214.el8fdp.aarch64.rpm python3-openvswitch2.13-debuginfo-2.13.0-214.el8fdp.aarch64.rpm noarch: openvswitch2.13-test-2.13.0-214.el8fdp.noarch.rpm ppc64le: network-scripts-openvswitch2.13-2.13.0-214.el8fdp.ppc64le.rpm openvswitch2.13-2.13.0-214.el8fdp.ppc64le.rpm openvswitch2.13-debuginfo-2.13.0-214.el8fdp.ppc64le.rpm openvswitch2.13-debugsource-2.13.0-214.el8fdp.ppc64le.rpm openvswitch2.13-devel-2.13.0-214.el8fdp.ppc64le.rpm openvswitch2.13-ipsec-2.13.0-214.el8fdp.ppc64le.rpm python3-openvswitch2.13-2.13.0-214.el8fdp.ppc64le.rpm python3-openvswitch2.13-debuginfo-2.13.0-214.el8fdp.ppc64le.rpm s390x: network-scripts-openvswitch2.13-2.13.0-214.el8fdp.s390x.rpm openvswitch2.13-2.13.0-214.el8fdp.s390x.rpm openvswitch2.13-debuginfo-2.13.0-214.el8fdp.s390x.rpm openvswitch2.13-debugsource-2.13.0-214.el8fdp.s390x.rpm openvswitch2.13-devel-2.13.0-214.el8fdp.s390x.rpm openvswitch2.13-ipsec-2.13.0-214.el8fdp.s390x.rpm python3-openvswitch2.13-2.13.0-214.el8fdp.s390x.rpm python3-openvswitch2.13-debuginfo-2.13.0-214.el8fdp.s390x.rpm x86_64: network-scripts-openvswitch2.13-2.13.0-214.el8fdp.x86_64.rpm openvswitch2.13-2.13.0-214.el8fdp.x86_64.rpm openvswitch2.13-debuginfo-2.13.0-214.el8fdp.x86_64.rpm openvswitch2.13-debugsource-2.13.0-214.el8fdp.x86_64.rpm openvswitch2.13-devel-2.13.0-214.el8fdp.x86_64.rpm openvswitch2.13-ipsec-2.13.0-214.el8fdp.x86_64.rpm python3-openvswitch2.13-2.13.0-214.el8fdp.x86_64.rpm python3-openvswitch2.13-debuginfo-2.13.0-214.el8fdp.x86_64.rpm These packages are GPG signed by Red Hat forsecurity. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-1668 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZD7GLtzjgjWX9erEAQgwsg/9FM6NZrAI8FDFFH4N1p57Sd4Ul56xok0m /VZ/YyAnINPnYcZCKAYpgBhilHyRgPzd2rqBxGx7eovYxcaD8a/YYEUvHjBsh7Zv z+26A8AGhwqJS+tFpUmVENre4pgOqoD8TMMP/39qYKSy3QFQZakGBpabPDdI65u+ uxPifmP/Pep5qLqxafwFAijiRpw7WgSFluXc8/OmrQEMAvAEvogW6blNkGv5KA+K B2XZCCRuuf1wyfUepNRIBJAXvzduUQ8hkuu8VbQtl37RsTtO/wAFmYIDpjH/RSvp V2NUfkDtbSg1Hg3x2CHr7FlDbxtECAe56yaECNipJTnqMaMOHhBGYU81wF7JCqT7 jQ6KA84jOj7bZnl2td9LguT/TqupA8qcOcMQnA63kau+rwWbywDhr3OD5baEqCL7 Yw2J6TH345GwASD2cfvMV+EIT9eXKeDzLl6pFbW6xgSmv84N4NZH2WFu5XRV5tNM htx4aa7YZ8Zeq+cX15/hNwbsaITxX2qOro8D3gveZfl3f7fdisrNRBW+CztmJmJQ fkNGz1jWqkN7/W/Tg9r/BpKYCTASO3Hz/rAfp7+Avmjaz7MxOELaXgNTLphxMCBK s6jtlfTosn+26Nmc0ftoZm7NbyB0OMCvihZu11dKGvdU7JukAYqqDUcBpT0sdgA5 2TUrqCBxF+c=r8Rc -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for openvswitch is now available in Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openvswitch security, bug fix and enhancement update Advisory ID: RHSA-2020:2298-01 Product: Fast Datapath Advisory URL: https://access.redhat.com/errata/RHSA-2020:2298 Issue date: 2020-05-26 CVE Names: CVE-2020-10722 CVE-2020-10723 ==================================================================== 1. Summary: An update for openvswitch is now available in Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Fast Datapath for Red Hat Enterprise Linux 7 - noarch, ppc64le, s390x, x86_64 3. Description: Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. Security Fix(es): * dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() (CVE-2020-10722) * dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() (CVE-2020-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * OVS causing high pings and latency inside guest VM when an active DPDK port fails (BZ#1822198) * SEGV after recirculation in batch processing in vswitchd 2.9.0 (BZ#1826886) 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1822198 - OVS causing high pings and latency inside guest VM when an active DPDK port fails 1826886 - SEGV after recirculation in batch processing in vswitchd 2.9.0 1828867 - CVE-2020-10722 dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() 1828874 - CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() 6. Package List: Fast Datapath for Red Hat Enterprise Linux 7: Source: openvswitch-2.9.0-130.el7fdp.src.rpm noarch: openvswitch-test-2.9.0-130.el7fdp.noarch.rpm ppc64le: openvswitch-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-debuginfo-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-devel-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-ovn-central-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-ovn-common-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-ovn-host-2.9.0-130.el7fdp.ppc64le.rpm openvswitch-ovn-vtep-2.9.0-130.el7fdp.ppc64le.rpm python-openvswitch-2.9.0-130.el7fdp.ppc64le.rpm s390x: openvswitch-2.9.0-130.el7fdp.s390x.rpm openvswitch-debuginfo-2.9.0-130.el7fdp.s390x.rpm openvswitch-devel-2.9.0-130.el7fdp.s390x.rpm openvswitch-ovn-central-2.9.0-130.el7fdp.s390x.rpm openvswitch-ovn-common-2.9.0-130.el7fdp.s390x.rpm openvswitch-ovn-host-2.9.0-130.el7fdp.s390x.rpm openvswitch-ovn-vtep-2.9.0-130.el7fdp.s390x.rpm python-openvswitch-2.9.0-130.el7fdp.s390x.rpm x86_64: openvswitch-2.9.0-130.el7fdp.x86_64.rpm openvswitch-debuginfo-2.9.0-130.el7fdp.x86_64.rpm openvswitch-devel-2.9.0-130.el7fdp.x86_64.rpm openvswitch-ovn-central-2.9.0-130.el7fdp.x86_64.rpm openvswitch-ovn-common-2.9.0-130.el7fdp.x86_64.rpm openvswitch-ovn-host-2.9.0-130.el7fdp.x86_64.rpm openvswitch-ovn-vtep-2.9.0-130.el7fdp.x86_64.rpm python-openvswitch-2.9.0-130.el7fdp.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-10722 https://access.redhat.com/security/cve/CVE-2020-10723 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXsz9ftzjgjWX9erEAQg78Q/+NAwENXoOtll40/HHkeqg7CZlfhopEVJg a9+PbanATMTUlyu39BjmlKXQ72s3Hqw8ovq6abq3GSdW01/kIEVeUh4gnQfX6fEJ 0nzAD2N2wpP/9zQRvEorkArgdlXL77nqBJhzla4owU9Sz5xVih7FwPAU8VIglqu+ h7WMn7l5BTc7JjJQedBWntOoe2ZXJO204xzw81HGHd0QWoLF6ff3j3gjqR8Kr4UZ 9IiD6Oq5EBp7+Fo9xsNZ8b68DyuiU3E7/PZhzQrtWXxNstPQP790kzAgClcvmvVr yCdduCfq/5uDV1Sa0kJy0u5sniaNyVHCOKJCDj8xCaEq3qMfKHwKvQ3scEIyelow Dw157fImj5hPT0O8+qbCpmB5ebd0ASmLEuUOsmRd1M8Swb7E7jvmRk5aYR55Hp50 Bg/0eSSWcBFSB+fsHUQHykuIao2rvBhKF5rnHyEcXB1Vjj+Nu1ImQ6bsUVuCDtID A+UNYINSdXJB1jkm6c+6sr9An/seIIsPV0n1UtAcaOEA5NEfnhu5d/OQw6tMvuTo da1X9Np9MP/HilV/EONq7j4r2RfdRpWCIbXFNtOi7jGzidbvzXeMfazzX3EZJO2t mMsdm8XpaJI8o29MOExC1UfxGyV0U6yvVPEX73IL3cCns0OVFCZ5zkrXptonVDc9 dORogp2lO2U=RH/2 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for openvswitch2.11 is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openvswitch2.11 security, bug fix and enhancement update Advisory ID: RHSA-2020:2296-01 Product: Fast Datapath Advisory URL: https://access.redhat.com/errata/RHSA-2020:2296 Issue date: 2020-05-26 CVE Names: CVE-2020-10722 CVE-2020-10723 CVE-2020-10724 ==================================================================== 1. Summary: An update for openvswitch2.11 is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Fast Datapath for Red Hat Enterprise Linux 7 - noarch, ppc64le, s390x, x86_64 3. Description: Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. Security Fix(es): * dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() (CVE-2020-10722) * dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() (CVE-2020-10723) * dpdk: librte_vhost Missing inputs validation in Vhost-crypto (CVE-2020-10724) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [RHEL7] Update OVS 2.11 to last branch-2.11 commit and DPDK 18.11.7 (BZ#1822653) * [RHEL7] ingressqdisc gets removed (BZ#1826826) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1822653 - [RHEL7] Update OVS 2.11 to last branch-2.11 commit and DPDK 18.11.7 1828867 - CVE-2020-10722 dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() 1828874 - CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() 1828884 - CVE-2020-10724 dpdk: librte_vhost Missing inputs validation in Vhost-crypto 6. Package List: Fast Datapath for Red Hat Enterprise Linux 7: Source: openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.src.rpm noarch: openvswitch2.11-test-2.11.0-54.20200327gita4efc59.el7fdp.noarch.rpm ppc64le: openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.ppc64le.rpm openvswitch2.11-debuginfo-2.11.0-54.20200327gita4efc59.el7fdp.ppc64le.rpm openvswitch2.11-devel-2.11.0-54.20200327gita4efc59.el7fdp.ppc64le.rpm python-openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.ppc64le.rpm s390x: openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.s390x.rpm openvswitch2.11-debuginfo-2.11.0-54.20200327gita4efc59.el7fdp.s390x.rpm openvswitch2.11-devel-2.11.0-54.20200327gita4efc59.el7fdp.s390x.rpm python-openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.s390x.rpm x86_64: openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.x86_64.rpm openvswitch2.11-debuginfo-2.11.0-54.20200327gita4efc59.el7fdp.x86_64.rpm openvswitch2.11-devel-2.11.0-54.20200327gita4efc59.el7fdp.x86_64.rpm python-openvswitch2.11-2.11.0-54.20200327gita4efc59.el7fdp.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2020-10722 https://access.redhat.com/security/cve/CVE-2020-10723 https://access.redhat.com/security/cve/CVE-2020-10724 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXsz8ytzjgjWX9erEAQiXZQ//aMxXu9DkoZ/bFskzC58dztRDkh02xb10 uQu7XikqlSfhQZgRjXeXZlDsitMH6kCXCzBo5HyZsb1v0YLpNaQwcSj6Uflt+1eO 1koH4HWnDAOQSgPMSpmOJ81TxaXbiG9J+LDzCawvoqtGc+lnYcFByQfKRsjh2kIn 9XrDsupFx8m+k5Pes7xEvjio5qVlPoCyo3chrHd6rr8CTHYknq4nztGj7SRaIFaS XXE9tGX8PtrWczfwkeGdkks9pHl9cltSzCo8/S8hN2xZ8bbrXQITvYx92XmL+yh+ eU1O7pbKyo4ZYI63GugkIju3B16jG0P5bHv7NB/SWdJyMdixLBfy9roUPPRq05lR HV3qM6mHLbgisFx9qqjX0oPp255Lyr5KByeQ+O2JOixbbixXxnhZ6/6PK82emyGO cEFzCyg+28VLw27FGLxs6yjLGRtIv8QjQZ/a+1zrx1J9HDAQZXJxYR+KU0dp2SKN AwpykOyUxrlreW9zOHmOOT//+/IQhl0xa7Mi7uyOwQFTC8XVAKVKhfC+p9/nLjmW 1AVUh9v4XXAvY/659jIWutbmaGyZjM9d5etiSX6y6/IUEuLyD7ec6Iioj8bWXcxM uMZGdbArYBl608HxuY6wbhrwvnqNLh6ec8gbNjFqckxWJ9BjNI9BnSE3HffeGT6G n8UU2+vl2TQ=9VaF -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.