A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nwproto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
Important: openvswitch3.1 security update
Important: openvswitch3.3 security update
Important: openvswitch3.1 security update
Important: openvswitch3.4 security update
Important: ovn24.09 security update
Important: ovn22.03 security update
Important: ovn23.06 security update
Important: ovn22.12 security update
Important: ovn23.06 security update
Important: ovn22.09 security update
Important: ovn23.09 security update
Important: ovn24.03 security update
Important: ovn22.06 security update
Important: ovn22.06 security update
Important: ovn22.12 security update
Important: ovn23.03 security update
Important: ovn22.03 security update
Important: ovn22.09 security update
Important: ovn23.03 security update
Important: tuned security update
Important: tuned security update
Moderate: tuned security update
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhostuser socket, can send specially crafted VRINGSETNUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
A flaw was found in the vhost library in DPDK. Function vhostusersetinflightfd() does not validate msg->payload.inflight.numqueues, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Important: ovn-2021 security update
Important: ovn23.03 security update
Important: ovn22.03 security update
Important: ovn22.12 security update