First published: Thu Feb 11 2021(Updated: )
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.<br>Security Fix(es):<br><li> openvswitch: limitation in the OVS packet parsing in userspace leads to DoS (CVE-2020-35498)</li> <li> lldp/openvswitch: denial of service via externally triggered memory leak (CVE-2020-27827)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [RFE] Add auto load balance params (BZ#1920121)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openvswitch2.13 | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/network-scripts-openvswitch2.13 | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/openvswitch2.13-debuginfo | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/openvswitch2.13-debugsource | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/openvswitch2.13-devel | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/openvswitch2.13-ipsec | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/openvswitch2.13-test | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/python3-openvswitch2.13 | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
redhat/python3-openvswitch2.13-debuginfo | <2.13.0-79.5.el8fd | 2.13.0-79.5.el8fd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:0497 is classified as Moderate according to Red Hat's advisory.
To fix RHSA-2021:0497, you should update the affected packages to version 2.13.0-79.5.el8fd.
The affected packages include openvswitch2.13, network-scripts-openvswitch2.13, and python3-openvswitch2.13, among others.
RHSA-2021:0497 addresses a denial of service vulnerability due to a limitation in OVS packet parsing in userspace (CVE-2020-35498).
Yes, the vulnerability addressed in RHSA-2021:0497 could lead to denial of service, impacting system performance.