First published: Fri May 27 2022(Updated: )
Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.<br>Security Fix(es):<br><li> openvswitch2.13: DPDK: Out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash (CVE-2021-3839)</li> <li> openvswitch2.13: DPDK: Sending vhost-user-inflight type messages could lead to DoS (CVE-2022-0669)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openvswitch2.13 | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/network-scripts-openvswitch2.13 | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/openvswitch2.13-debuginfo | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/openvswitch2.13-debugsource | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/openvswitch2.13-devel | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/openvswitch2.13-ipsec | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/openvswitch2.13-test | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/python3-openvswitch2.13 | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
redhat/python3-openvswitch2.13-debuginfo | <2.13.0-180.el8fd | 2.13.0-180.el8fd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:4786 is classified as important due to the potential for crashes resulting from out-of-bounds read/write issues.
To fix RHSA-2022:4786, you should upgrade to version 2.13.0-180.el8fd of the affected Open vSwitch packages.
RHSA-2022:4786 addresses a vulnerability in openvswitch2.13 related to an out-of-bounds read/write in the vhost_user_set_inflight_fd() function.
Affected packages in RHSA-2022:4786 include openvswitch2.13, network-scripts-openvswitch2.13, and python3-openvswitch2.13 among others.
Yes, RHSA-2022:4786 specifically affects Open vSwitch version 2.13.0-180.el8fd.