USN-5242-1: Open vSwitch vulnerability
It was discovered that Open vSwitch incorrectly handled certain fragmented packets. A remote attacker could possibly use this issue to cause Open vSwitch to consume resources, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Open vSwitch vulnerability?
The vulnerability ID of this Open vSwitch vulnerability is CVE-2021-3905.
What is the severity of CVE-2021-3905?
The severity of CVE-2021-3905 is not mentioned in the provided information, please refer to the references for more details.
How can a remote attacker exploit the vulnerability?
A remote attacker can exploit the vulnerability by sending certain fragmented packets to the affected Open vSwitch, causing it to consume resources and leading to a denial of service.
Which versions of Open vSwitch are affected by CVE-2021-3905?
The version affected by CVE-2021-3905 is openvswitch-common 2.16.0-0ubuntu2.1.
How can I fix the vulnerability in Open vSwitch?
To fix the vulnerability, update to openvswitch-common version 2.16.0-0ubuntu2.1 or later as per the provided references.