RHSA-2021:0497: Moderate: openvswitch2.13 security and bug fix update
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.Security Fix(es): openvswitch: limitation in the OVS packet parsing in userspace leads to DoS (CVE-2020-35498) lldp/openvswitch: denial of service via externally triggered memory leak (CVE-2020-27827) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [RFE] Add auto load balance params (BZ#1920121)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/openvswitch2.13to a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/network-scripts-openvswitch2.13to a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/openvswitch2.13-debuginfoto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/openvswitch2.13-debugsourceto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/openvswitch2.13-develto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/openvswitch2.13-ipsecto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/openvswitch2.13-testto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/python3-openvswitch2.13to a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd - Upgrade
Upgrade
redhat/python3-openvswitch2.13-debuginfoto a version that resolves this vulnerability.Fixed in 2.13.0-79.5.el8fd
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0497?
The severity of RHSA-2021:0497 is classified as Moderate according to Red Hat's advisory.
How do I fix RHSA-2021:0497?
To fix RHSA-2021:0497, you should update the affected packages to version 2.13.0-79.5.el8fd.
Which packages are affected by RHSA-2021:0497?
The affected packages include openvswitch2.13, network-scripts-openvswitch2.13, and python3-openvswitch2.13, among others.
What specific vulnerability does RHSA-2021:0497 address?
RHSA-2021:0497 addresses a denial of service vulnerability due to a limitation in OVS packet parsing in userspace (CVE-2020-35498).
Is there any impact on system performance due to RHSA-2021:0497?
Yes, the vulnerability addressed in RHSA-2021:0497 could lead to denial of service, impacting system performance.