QID 239168
Date Published: 2021-03-24
QID 239168: Red Hat Update for openvswitch2.11 and ovn2.11 (RHSA-2021:0931)
Open vSwitch provides standard network bridging functions and support forthe OpenFlow protocol for remote per-flow control of traffic.OVN, the Open Virtual Network, is a system to support virtual networkabstraction. OVN complements the existing capabilities of OVS to add native support for virtual network abstractions, such as virtual L2 and L3 overlays and security groups.
Security Fix(es): buffer overflow in the lldp_decode function in daemon/protocols/lldp.c (CVE-2015-8011)
librte_vhost Integer overflow in vhost_user_set_log_base()
(CVE-2020-10722)
librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
(CVE-2020-10723)
librte_vhost Missing inputs validation in Vhost-crypto (CVE-2020-10724)
Affected Products:
Red Hat OpenStack 13 x86_64
Red Hat OpenStack for IBM Power 13 ppc64le
Red Hat OpenStack Director Deployment Tools 13 x86_64
Red Hat OpenStack Director Deployment Tools for IBM Power LE 13 ppc64le
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
On successful exploitation, it could allow an attacker to execute code.
Refer to Red Hat security advisory RHSA-2021:0931 to address this issue and obtain more information.
- RHSA-2021:0931 -
access.redhat.com/errata/RHSA-2021:0931?language=en
CVEs related to QID 239168
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| RHSA-2021:0931 | Red Hat Enterprise Linux |
|