[ubuntu/bionic-security] openvswitch 2.9.2-0ubuntu0.18.04.3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Jan 30 12:26:57 UTC 2019


openvswitch (2.9.2-0ubuntu0.18.04.3) bionic-security; urgency=medium

  * SECURITY UPDATE: assertion failure when decoding a group mod
    - debian/patches/CVE-2018-17204.patch: don't assert-fail decoding bad
      OF1.5 group mod type or command in lib/ofp-util.c.
    - CVE-2018-17204
  * SECURITY UPDATE: assertion failure when adding flows
    - debian/patches/CVE-2018-17205.patch: fix OVS crash when reverting old
      flows in bundle commit in ofproto/ofproto.c.
    - CVE-2018-17205
  * SECURITY UPDATE: buffer overread during BUNDLE action decoding
    - debian/patches/CVE-2018-17206.patch: avoid overread in
      lib/ofp-actions.c.
    - CVE-2018-17206

Date: 2018-10-25 15:02:22.275712+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list