OESA-2021-1179
Dashboard / Vulnerabilities / OESA-2021-1179
OESA-2021-1179
Summary: openvswitch security update
Details: Open vSwitch is a production quality, multilayer virtual switch licensed under the open source Apache 2.0 license. Security Fix(es): A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.(CVE-2020-35498) A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.(CVE-2020-27827) Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.(CVE-2015-8011)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1179, https://nvd.nist.gov/vuln/detail/CVE-2020-35498, https://nvd.nist.gov/vuln/detail/CVE-2020-27827, https://nvd.nist.gov/vuln/detail/CVE-2015-8011
Affected packages
Package
Name: openvswitch
Purl: pkg:rpm/openEuler/openvswitch&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
