First published: Wed Mar 15 2023(Updated: )
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/openvswitch | <2.17.9<3.0.6<3.1.4<3.2.2 | 2.17.9 3.0.6 3.1.4 3.2.2 |
ubuntu/openvswitch | <2.13.8-0ubuntu1.4 | 2.13.8-0ubuntu1.4 |
ubuntu/openvswitch | <2.17.9-0ubuntu0.22.04.1 | 2.17.9-0ubuntu0.22.04.1 |
ubuntu/openvswitch | <3.2.2-0ubuntu0.23.10.1 | 3.2.2-0ubuntu0.23.10.1 |
redhat/openvswitch | <3.1.0 | 3.1.0 |
debian/openvswitch | 2.10.7+ds1-0+deb10u1 2.10.7+ds1-0+deb10u5 2.15.0+ds1-2+deb11u5 3.1.0-2+deb12u1 3.3.0-1 |
Disable flow hardware offload if enabled via the following setting and reboot: other_config:hw-offload=false
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.