RHSA-2020:2295: Important: openvswitch2.13 security, bug fix and enhancement update
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.Security Fix(es): dpdk: librtevhost Malicious guest could cause segfault by sending invalid Virtio descriptor (CVE-2020-10725) dpdk: librtevhost Interger overflow in vhostusersetlogbase() (CVE-2020-10722) dpdk: librtevhost Integer truncation in vhostusercheckandallocqueuepair() (CVE-2020-10723) dpdk: librtevhost Missing inputs validation in Vhost-crypto (CVE-2020-10724) dpdk: librtevhost VHOSTUSERGETINFLIGHTFD message flooding to result in a DoS (CVE-2020-10726) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): DPDK virtiouser lack of notifications make vhostnet+napi stops tx buffers (BZ#1803082) Update internal DPDK to 19.11.1 (BZ#1824825)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2295?
The severity of RHSA-2020:2295 is classified as high due to potential segmentation faults caused by malicious guest interactions.
How do I fix RHSA-2020:2295?
To fix RHSA-2020:2295, update the openvswitch packages to version 2.13.0-25.el8fd or later.
What vulnerabilities are addressed in RHSA-2020:2295?
RHSA-2020:2295 addresses the CVE-2020-10725 vulnerability that allows malicious guests to cause segmentation faults.
Which software versions are affected by RHSA-2020:2295?
The affected software versions for RHSA-2020:2295 include openvswitch2.13 and related packages up to 2.13.0-25.el8fd.
Is there a need to restart services after applying the fix for RHSA-2020:2295?
Yes, it is recommended to restart the Open vSwitch service after applying the fix for RHSA-2020:2295.