Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:2360-1

Опубликовано: 02 июн. 2023
Источник: suse-cvrf

Описание

Security update for openvswitch

This update for openvswitch fixes the following issues:

  • CVE-2022-4338: Fixed Integer Underflow in Organization Specific TLV (bsc#1206580).
  • CVE-2022-4337: Fixed Out-of-Bounds Read in Organization Specific TLV (bsc#1206581).
  • CVE-2022-32166: Fixed a out of bounds read in minimask_equal() (bsc#1203865).
  • CVE-2021-36980: Fixed a use-after-free issue during the decoding of a RAW_ENCAP action (bsc#1188524).

Список пакетов

SUSE Linux Enterprise Server 12 SP4-ESPOS
libopenvswitch-2_8-0-2.8.10-4.33.1
openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS
libopenvswitch-2_8-0-2.8.10-4.33.1
openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libopenvswitch-2_8-0-2.8.10-4.33.1
openvswitch-2.8.10-4.33.1
SUSE OpenStack Cloud 9
libopenvswitch-2_8-0-2.8.10-4.33.1
openvswitch-2.8.10-4.33.1
SUSE OpenStack Cloud Crowbar 9
libopenvswitch-2_8-0-2.8.10-4.33.1
openvswitch-2.8.10-4.33.1

Описание

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:openvswitch-2.8.10-4.33.1

Ссылки

Описание

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of "minimasks" function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:openvswitch-2.8.10-4.33.1

Ссылки

Описание

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:openvswitch-2.8.10-4.33.1

Ссылки

Описание

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libopenvswitch-2_8-0-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4-LTSS:openvswitch-2.8.10-4.33.1

Ссылки
Уязвимость SUSE-SU-2023:2360-1