RHSA-2020:2296: Moderate: openvswitch2.11 security, bug fix and enhancement update
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.<br>Security Fix(es):<br><li> dpdk: librtevhost Interger overflow in vhostusersetlogbase() (CVE-2020-10722)</li> <li> dpdk: librtevhost Integer truncation in vhostusercheckandallocqueuepair() (CVE-2020-10723)</li> <li> dpdk: librtevhost Missing inputs validation in Vhost-crypto (CVE-2020-10724)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [RHEL7] Update OVS 2.11 to last branch-2.11 commit and DPDK 18.11.7 (BZ#1822653)</li> <li> [RHEL7] ingress qdisc gets removed (BZ#1826826)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2296?
The severity of RHSA-2020:2296 is classified as important.
How do I fix RHSA-2020:2296?
To fix RHSA-2020:2296, update to the latest version of Open vSwitch, specifically 2.11.0-54.20200327gita4efc59.el7fd.
What vulnerabilities are addressed by RHSA-2020:2296?
RHSA-2020:2296 addresses an integer overflow vulnerability in vhost_user_set_log_base() from the DPDK librte_vhost.
What packages are affected by RHSA-2020:2296?
The affected packages include openvswitch2.11, openvswitch2.11-debuginfo, openvswitch2.11-devel, openvswitch2.11-test, and python-openvswitch2.11.
Is RHSA-2020:2296 a critical vulnerability?
RHSA-2020:2296 is not classified as critical but is considered important due to the potential impact on the system.