• [gentoo-announce] [ GLSA 202311-16 ] Open vSwitch: Multiple Vulnerabili

    From glsamaker@gentoo.org@21:1/5 to All on Sun Nov 26 11:20:01 2023
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202311-16
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Low
    Title: Open vSwitch: Multiple Vulnerabilities
    Date: November 26, 2023
    Bugs: #765346, #769995, #803107, #887561
    ID: 202311-16

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple denial of service vulnerabilites have been found in Open
    vSwitch.

    Background
    ==========

    Open vSwitch is a production quality multilayer virtual switch.

    Affected packages
    =================

    Package Vulnerable Unaffected
    -------------------- ------------ ------------
    net-misc/openvswitch < 2.17.6 >= 2.17.6

    Description
    ===========

    Multiple vulnerabilities have been discovered in Open vSwitch. Please
    review the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Open vSwitch users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-misc/openvswitch-2.17.6"

    References
    ==========

    [ 1 ] CVE-2020-27827
    https://nvd.nist.gov/vuln/detail/CVE-2020-27827
    [ 2 ] CVE-2020-35498
    https://nvd.nist.gov/vuln/detail/CVE-2020-35498
    [ 3 ] CVE-2021-3905
    https://nvd.nist.gov/vuln/detail/CVE-2021-3905
    [ 4 ] CVE-2021-36980
    https://nvd.nist.gov/vuln/detail/CVE-2021-36980
    [ 5 ] CVE-2022-4337
    https://nvd.nist.gov/vuln/detail/CVE-2022-4337
    [ 6 ] CVE-2022-4338
    https://nvd.nist.gov/vuln/detail/CVE-2022-4338
    [ 7 ] CVE-2023-1668
    https://nvd.nist.gov/vuln/detail/CVE-2023-1668

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202311-16

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2023 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmVjGTQACgkQFMQkOaVy +9mo7hAAoJFSGzIYDqTH0WKPVqRWeLar1sj9QccCzidWnLpA31Sqj6iSswXR65fO y94vj420VIRkFr4KF12CEdjA+YfM+aBU4ZtnXjZKax2YgEx8U2KmDsG5dyQ/YLih Q9I0h2z7+3GMBmzKpxvNi20QOXfOXMeTkFBmckkmKiK0UB24OM7/6OCtdTZMkNCY jYkrcjOJzXfmlK1t3421YlHr8T9+b7FkwpzjPlykVfDYd88J3GAHnTJ5I1nkaebD rH/BxS8JJDneu6F5U29TwKze1FCzKvqyKP6KyBt8SbkPIj5eslb8U1gb6ezcEe1P C+glaFSSnISTxaMQHbmcaKLDeD1KYcFIlJ8mZTh1vmWNhECizUNEnkw+S09ehyrd IPPQIYyg/fNweWEAfvAS4F6r07dDZI8XTr1mn07sJ/fzyOhKX7VaKs8f+ebijnD5 jYxsyODSUDZq7gm22sSzuiBUdXRWMPwSH8jg1ViutjrSdoRWiFTaOKSyYn5ShfOu djSC8NnnG2BhIssYsW++qt8ayGBdlXj7o4MW6Jw2NbDVdrRn1W9vtSj6KtRFO7TO L5hoaPcWortFfP1C6H7+JMpExMGiKOgn0E3JSyIQnhuk9SqtQf2nH+tWBF1SOVz6 tOy0LflmQw2ifzp7Uuu7Rc4pqlTr5GwKGQ0NrXVtPDJsY0kzK10=
    =b3RZ
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)