First published: Tue May 26 2020(Updated: )
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.<br>Security Fix(es):<br><li> dpdk: librte_vhost Malicious guest could cause segfault by sending invalid Virtio descriptor (CVE-2020-10725)</li> <li> dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() (CVE-2020-10722)</li> <li> dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() (CVE-2020-10723)</li> <li> dpdk: librte_vhost Missing inputs validation in Vhost-crypto (CVE-2020-10724)</li> <li> dpdk: librte_vhost VHOST_USER_GET_INFLIGHT_FD message flooding to result in a DoS (CVE-2020-10726)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> DPDK virtio_user lack of notifications make vhost_net+napi stops tx buffers (BZ#1803082)</li> <li> Update internal DPDK to 19.11.1 (BZ#1824825)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openvswitch2.13 | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/network-scripts-openvswitch2.13 | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/openvswitch2.13-debuginfo | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/openvswitch2.13-debugsource | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/openvswitch2.13-devel | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/openvswitch2.13-test | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/python3-openvswitch2.13 | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
redhat/python3-openvswitch2.13-debuginfo | <2.13.0-25.el8fd | 2.13.0-25.el8fd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.