Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 803107 (CVE-2021-36980, CVE-2021-3905) - <net-misc/openvswitch-2.17.2: multiple vulnerabilities
Summary: <net-misc/openvswitch-2.17.2: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2021-36980, CVE-2021-3905
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugs.chromium.org/p/oss-fuzz/...
Whiteboard: B3 [glsa+]
Keywords:
Depends on: 864813
Blocks:
  Show dependency tree
 
Reported: 2021-07-20 22:14 UTC by John Helmert III
Modified: 2023-11-26 10:09 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-20 22:14:17 UTC
CVE-2021-36980:

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

2.14 patch: https://github.com/openvswitch/ovs/commit/8ce8dc34b5f73b30ce0c1869af9947013c3c6575
2.15 patch: https://github.com/openvswitch/ovs/commit/38744b1bcb022c611712527f039722115300f58f

The vulnerability is fixed in the 2.15 branch with 2.15.1 and there seems to
be no release with 2.14's fix.
Comment 1 NATTkA bot gentoo-dev 2021-07-29 17:20:53 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:29:00 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:36:57 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:44:59 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:53:03 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:56:58 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:00:58 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 18:09:16 UTC
Package list is empty or all packages have requested keywords.
Comment 9 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-07 06:16:03 UTC
Ping.
Comment 10 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 15:54:37 UTC
Please stabilize when ready.
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-23 20:01:09 UTC
CVE-2021-3905:

A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

RedHat bug: https://bugzilla.redhat.com/show_bug.cgi?id=2019692
Issue: https://github.com/openvswitch/ovs-issues/issues/226
Commit: https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349

Commit is in 2.17.0 and beyond.
Comment 12 Larry the Git Cow gentoo-dev 2023-11-26 10:07:46 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=6109db58da8356109819f2e31a15acb75bbd5b61

commit 6109db58da8356109819f2e31a15acb75bbd5b61
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-11-26 10:06:58 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2023-11-26 10:07:30 +0000

    [ GLSA 202311-16 ] Open vSwitch: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/765346
    Bug: https://bugs.gentoo.org/769995
    Bug: https://bugs.gentoo.org/803107
    Bug: https://bugs.gentoo.org/887561
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202311-16.xml | 51 +++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 51 insertions(+)