CVE-2021-36980: Use After Free
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decodeNXASTRAWENCAP (called from ofpactdecode and ofpactsdecode) during the decoding of a RAWENCAP action.
Other sources
Open vSwitch (aka openvswitch) has a use-after-free in decodeNXASTRAWENCAP (called from ofpactdecode and ofpactsdecode) during the decoding of a RAWENCAP action.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-36980?
CVE-2021-36980 is a vulnerability in Open vSwitch (aka openvswitch) that allows for a use-after-free in decode_NXAST_RAW_ENCAP during the decoding of a RAW_ENCAP action.
What is the severity of CVE-2021-36980?
The severity of CVE-2021-36980 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-36980?
Open vSwitch versions 2.11.0 through 2.15.0 are affected by CVE-2021-36980.
How can I fix CVE-2021-36980?
To fix CVE-2021-36980, you need to update Open vSwitch to version 2.13.4 if you are using version 2.11.0 to 2.13.0, or to version 2.15.1 if you are using version 2.15.0.
Where can I find more information about CVE-2021-36980?
You can find more information about CVE-2021-36980 in the referenced links: [link1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851), [link2](https://github.com/openvswitch/ovs/commit/77cccc74deede443e8b9102299efc869a52b65b2), [link3](https://github.com/openvswitch/ovs/commit/65c61b0c23a0d474696d7b1cea522a5016a8aeb3).