RHSA-2020:2297: Moderate: openvswitch2.11 security, bug fix and enhancement update
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.Security Fix(es): dpdk: librtevhost Interger overflow in vhostusersetlogbase() (CVE-2020-10722) dpdk: librtevhost Integer truncation in vhostusercheckandallocqueuepair() (CVE-2020-10723) dpdk: librtevhost Missing inputs validation in Vhost-crypto (CVE-2020-10724) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [RHEL8] Update OVS 2.11 to last branch-2.11 commit and DPDK 18.11.7 (BZ#1822654) [RHEL8] ingress qdisc gets removed (BZ#1826827)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2297?
The severity of RHSA-2020:2297 is classified as important.
How do I fix RHSA-2020:2297?
To fix RHSA-2020:2297, you need to update the openvswitch packages to version 2.11.0-54.20200327gita4efc59.el8fd.
What specific vulnerabilities are addressed in RHSA-2020:2297?
RHSA-2020:2297 addresses an integer overflow vulnerability in vhost_user_set_log_base() (CVE-2020-10722).
Which versions of openvswitch are affected by RHSA-2020:2297?
RHSA-2020:2297 affects openvswitch version 2.11.0-54.20200327gita4efc59.el8fd and earlier.
Is it necessary to reboot after applying the fix for RHSA-2020:2297?
Yes, it is recommended to reboot the system after applying the fix for RHSA-2020:2297 to ensure all changes take effect.