* bsc#1236353 Cross-References: * CVE-2025-0650 . # Security update for openvswitch3 Announcement ID: SUSE-SU-2025:0742-1 Release Date: 2025-02-28T10:17:43Z Rating: important References: * bsc#1236353 Cross-References: * CVE-2025-0650 CVSS scores: * CVE-2025-0650 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-0650 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0650 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openvswitch3 fixes the following issues: * CVE-2025-0650: Fixed egress ACLs that may be bypassed via specially crafted UDP packet (bsc#1236353). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-742=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-742=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-742=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-742=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-742=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP5-LTSS-2025-742=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-742=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * openSUSE Leap 15.5 (noarch) * openvswitch3-doc-3.1.0-150500.3.22.1 * ovn3-doc-23.03.0-150500.3.22.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * openSUSE Leap 15.6 (noarch) * openvswitch3-doc-3.1.0-150500.3.22.1 * ovn3-doc-23.03.0-150500.3.22.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 *ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 *openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 * ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenvswitch-3_1-0-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-ipsec-3.1.0-150500.3.22.1 * openvswitch3-test-3.1.0-150500.3.22.1 * openvswitch3-pki-3.1.0-150500.3.22.1 * libopenvswitch-3_1-0-3.1.0-150500.3.22.1 * ovn3-debuginfo-23.03.0-150500.3.22.1 * python3-ovs3-3.1.0-150500.3.22.1 * ovn3-host-23.03.0-150500.3.22.1 * ovn3-docker-23.03.0-150500.3.22.1 * openvswitch3-debugsource-3.1.0-150500.3.22.1 * ovn3-23.03.0-150500.3.22.1 * openvswitch3-devel-3.1.0-150500.3.22.1 * libovn-23_03-0-debuginfo-23.03.0-150500.3.22.1 * ovn3-central-23.03.0-150500.3.22.1 * ovn3-vtep-23.03.0-150500.3.22.1 * openvswitch3-test-debuginfo-3.1.0-150500.3.22.1 * ovn3-devel-23.03.0-150500.3.22.1 * ovn3-vtep-debuginfo-23.03.0-150500.3.22.1 * ovn3-host-debuginfo-23.03.0-150500.3.22.1 * libovn-23_03-0-23.03.0-150500.3.22.1 *ovn3-central-debuginfo-23.03.0-150500.3.22.1 * openvswitch3-vtep-3.1.0-150500.3.22.1 * openvswitch3-3.1.0-150500.3.22.1 * openvswitch3-debuginfo-3.1.0-150500.3.22.1 * openvswitch3-vtep-debuginfo-3.1.0-150500.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0650.html * https://bugzilla.suse.com/show_bug.cgi?id=1236353 . Uncover the essential security update from SUSE for openvswitch3 that fixes severe UDP packet escaping vulnerabilities.. openvswitch3 Security Updates, SUSE Linux Security, Critical Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in libslirp.. =========================================================================Ubuntu Security Notice USN-5009-1 July 15, 2021 libslirp vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libslirp. Software Description: - libslirp: General purpose TCP-IP emulator library Details: Qiuhao Li discovered that libslirp incorrectly handled certain header data lengths. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130) It was discovered that libslirp incorrectly handled certain udp packets. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libslirp0 4.4.0-1ubuntu0.1 Ubuntu 20.10: libslirp0 4.3.1-1ubuntu0.1 Ubuntu 20.04 LTS: libslirp0 4.1.0-2ubuntu2.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: CVE-2020-29129, CVE-2020-29130, CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595 Package Information: https://launchpad.net/ubuntu/+source/libslirp/4.4.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libslirp/4.3.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libslirp/4.1.0-2ubuntu2.2 . Patches addressing libslirp security issues can be found across multiple Ubuntu releases. Ensure your systems are up-to-date to prevent data exposures.. libslirp Updates, Ubuntu Security,Information Leak Fix, TCP-IP Emulator, 2021 Security Advisories. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.