[ubuntu/focal-security] openvswitch 2.13.8-0ubuntu1.4 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Mar 12 11:22:24 UTC 2024


openvswitch (2.13.8-0ubuntu1.4) focal-security; urgency=medium

  * SECURITY UPDATE: Incomplete fix for CVE-2023-5366
    - debian/patches/CVE-2023-5366-2.patch: follow Open Flow spec
      converting from OF to DP in lib/odp-util.c, tests/ofproto-macros.at,
      tests/system-traffic.at.
    - CVE-2023-5366
  * SECURITY UPDATE: vulnerable to crafted Geneve packets
    - debian/patches/CVE-2023-3966.patch: check geneve metadata length in
      lib/netdev-offload-tc.c, tests/system-offloads-traffic.at.
    - CVE-2023-3966

Date: 2024-03-04 16:28:09.922028+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/openvswitch/2.13.8-0ubuntu1.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list