[Bug 2147329] Re: [SRU] openvswitch 3.3.9 point release

Andreas Hasenack 2147329 at bugs.launchpad.net
Fri Jun 12 14:01:32 UTC 2026


Version 3.3.9 is fixing a CVE:

v3.3.9 - 31 Mar 2026
--------------------
   - Bug fixes
   - DPDK:
     * OVS validated with DPDK 23.11.6.
   - Security:
     * Fixed buffer overflow during conntrack processing of alg=ftp in
       userspace datapath (CVE-2026-34956).

This indicates that it should go through the security team, or at least
be built with just security enabled, copied to proposed, and then
released to both updates and security. Or something like that.

Has the security team been approached? I also checked 3.3.0-1ubuntu3.2
currently in noble-security, but I don't see a mention of this CVE in
d/changelog.

I'm subscribing ubuntu-security to the bug, and marking it as incomplete
to highlight that more information (and possibly a process change) is
needed.

** CVE added: https://cve.org/CVERecord?id=CVE-2026-34956

** Changed in: openvswitch (Ubuntu Noble)
       Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to openvswitch in Ubuntu.
https://bugs.launchpad.net/bugs/2147329

Title:
  [SRU] openvswitch 3.3.9 point release

Status in Ubuntu Cloud Archive:
  New
Status in openvswitch package in Ubuntu:
  Invalid
Status in openvswitch source package in Noble:
  Incomplete

Bug description:
  [Impact]
  This release sports mostly bug-fixes and we would like to make sure all of our
  supported customers have access to these improvements.

  The update contains the following package updates:

     * openvswitch 3.3.9

  For more details see:

     * https://www.openvswitch.org/releases/NEWS-3.3.9.txt
     * https://github.com/openvswitch/ovs/compare/v3.3.4...v3.3.9

  It will include [1] which can thereby be dropped from the delta.

  [1]:
  https://github.com/openvswitch/ovs/commit/ed87bdf9e650cfaca1925765cb9206a69faca3c2

  [Test Case]

  The following SRU process was followed:

  https://wiki.ubuntu.com/OpenStack/StableReleaseUpdates

  In order to avoid regression of existing consumers, the OpenStack team will
  run their continuous integration test against the packages that are in
  -proposed. A successful run of all available tests will be required before the
  proposed packages can be let into -updates.

  The OpenStack team will be in charge of attaching the output summary of the
  executed tests. The OpenStack team members will not mark ‘verification-done’ until
  this has happened.

  [Regression Potential]
  In order to mitigate the regression potential, the results of the
  aforementioned tests are attached to this bug.

  [other Info]
  ​​This is a regular update policy, it follows many others:
  - #1021530 [SRU] update to include stable fixes for OVS 1.4
  - #1470120 [SRU] openvswitch 2.3.2
  - #1641956 [SRU] openvswitch 2.6.1
  - #2003059 [SRU] openvswitch 3.0.3 point release
  - #2003060 [SRU] openvswitch 2.17.5 point release
  - #2025319 [SRU] openvswitch 3.1.2 point release
  - #2025323 [SRU] openvswitch 2.17.7 point release
  - #2039906 [SRU] openvswitch 3.2.1 point release
  - #2039907 [SRU] openvswitch 3.1.3 point release
  - #2039908 [SRU] openvswitch 2.17.8 point release

To manage notifications about this bug go to:
https://bugs.launchpad.net/cloud-archive/+bug/2147329/+subscriptions




More information about the Ubuntu-openstack-bugs mailing list