[Bug 2025319] Re: [SRU] Sync openvswitch 3.1.2 point release from Debian unstable
Frode Nordahl
2025319 at bugs.launchpad.net
Thu Jun 29 06:41:55 UTC 2023
This bug will be fixed in the package openvswitch - 3.1.2-1
---------------
openvswitch (3.1.2-1) unstable; urgency=medium
* Team upload.
* Update upstream source from tag 'upstream/3.1.2'.
* d/p/CVE-2023-1668_ofproto-dpif-xlate_Always_mask_ip_proto_field.patch:
Drop, included in new upstream version.
* d/control: Add libnuma-dev on s390x for AF_XDP.
* d/p/drop-old-autopkgtest: Drop old autopkgtest.
* debian/tests: Run upstream system tests as autopkgtests.
-- Frode Nordahl <frode.nordahl at canonical.com> Tue, 27 Jun 2023
19:13:06 +0200
openvswitch (3.1.0-2) unstable; urgency=high
* CVE-2023-1668: Remote traffic denial of service via crafted packets with IP
proto 0. Applied upstream patch: ofproto-dpif-xlate: Always mask ip proto
field (Closes: #1034042).
-- Thomas Goirand <zigo at debian.org> Tue, 11 Apr 2023 11:54:40 +0200
** Also affects: cloud-archive
Importance: Undecided
Status: New
** Also affects: cloud-archive/antelope
Importance: Undecided
Status: New
** Changed in: cloud-archive
Status: New => Invalid
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-1668
** Changed in: openvswitch (Ubuntu Lunar)
Status: Triaged => In Progress
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to openvswitch in Ubuntu.
https://bugs.launchpad.net/bugs/2025319
Title:
[SRU] Sync openvswitch 3.1.2 point release from Debian unstable
Status in Ubuntu Cloud Archive:
Invalid
Status in Ubuntu Cloud Archive antelope series:
New
Status in openvswitch package in Ubuntu:
Invalid
Status in openvswitch source package in Lunar:
In Progress
Bug description:
[Impact]
This release sports mostly bug-fixes and we would like to make sure all of our
supported customers have access to these improvements.
The update contains the following package updates:
* openvswitch 3.1.2
[Test Case]
The following SRU process was followed:
https://wiki.ubuntu.com/OpenStack/StableReleaseUpdates
In order to avoid regression of existing consumers, the OpenStack team will
run their continuous integration test against the packages that are in
-proposed. A successful run of all available tests will be required before the
proposed packages can be let into -updates.
The OpenStack team will be in charge of attaching the output summary of the
executed tests. The OpenStack team members will not mark ‘verification-done’ until
this has happened.
[Regression Potential]
In order to mitigate the regression potential, the results of the
aforementioned tests are attached to this bug.
To manage notifications about this bug go to:
https://bugs.launchpad.net/cloud-archive/+bug/2025319/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list