-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.0907
                        openvswitch security update
                               16 March 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           openvswitch
Publisher:         Red Hat
Operating System:  Red Hat
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-35498 CVE-2020-27827 

Reference:         ESB-2021.0639
                   ESB-2021.0559
                   ESB-2021.0520

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2021:0834
   https://access.redhat.com/errata/RHSA-2021:0837
   https://access.redhat.com/errata/RHSA-2021:0835

Comment: This bulletin contains three (3) Red Hat security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: openvswitch2.11 security update
Advisory ID:       RHSA-2021:0834-01
Product:           Fast Datapath
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0834
Issue date:        2021-03-15
CVE Names:         CVE-2020-27827 CVE-2020-35498 
=====================================================================

1. Summary:

An update for openvswitch2.11 is now available in Fast Datapath for Red Hat
Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Fast Datapath for Red Hat Enterprise Linux 7 - noarch, ppc64le, s390x, x86_64

3. Description:

Open vSwitch provides standard network bridging functions and support for
the OpenFlow protocol for remote per-flow control of traffic.

Security Fix(es):

* openvswitch: limitation in the OVS packet parsing in userspace leads to
DoS (CVE-2020-35498)

* lldp/openvswitch: denial of service via externally triggered memory leak
(CVE-2020-27827)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1908845 - CVE-2020-35498 openvswitch: limitation in the OVS packet parsing in userspace leads to DoS
1921438 - CVE-2020-27827 lldp/openvswitch: denial of service via externally triggered memory leak

6. Package List:

Fast Datapath for Red Hat Enterprise Linux 7:

Source:
openvswitch2.11-2.11.3-86.el7fdp.src.rpm

noarch:
openvswitch2.11-test-2.11.3-86.el7fdp.noarch.rpm

ppc64le:
openvswitch2.11-2.11.3-86.el7fdp.ppc64le.rpm
openvswitch2.11-debuginfo-2.11.3-86.el7fdp.ppc64le.rpm
openvswitch2.11-devel-2.11.3-86.el7fdp.ppc64le.rpm
python-openvswitch2.11-2.11.3-86.el7fdp.ppc64le.rpm

s390x:
openvswitch2.11-2.11.3-86.el7fdp.s390x.rpm
openvswitch2.11-debuginfo-2.11.3-86.el7fdp.s390x.rpm
openvswitch2.11-devel-2.11.3-86.el7fdp.s390x.rpm
python-openvswitch2.11-2.11.3-86.el7fdp.s390x.rpm

x86_64:
openvswitch2.11-2.11.3-86.el7fdp.x86_64.rpm
openvswitch2.11-debuginfo-2.11.3-86.el7fdp.x86_64.rpm
openvswitch2.11-devel-2.11.3-86.el7fdp.x86_64.rpm
python-openvswitch2.11-2.11.3-86.el7fdp.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-27827
https://access.redhat.com/security/cve/CVE-2020-35498
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYE9xHtzjgjWX9erEAQjwVBAAkRuAaKeYk3oEV7DcV71G9uGyU0dxuMv/
hEplUvevYEqAJrl9O4+Vtt4oLI/Rs/lNVu+vlS81ycMFXcJ4Gv5kCzJCM0Dq7iuY
K63hJtKtUhDwXYymkSfTansrf3TNJcDsUsm1vfhedN47drUG6KUEBurFhmLx0WXC
XoVtTWLaiqZIavYxRSWHaCOdTVHe+qM1DbBkGV5AhxxduHKVBRsBNXNHZk7O3nZ1
TmbMHIChTu8ixS/spYuBAnaoBCxFApIM/N+NpoTZzgVG1U2oANLksUdsS5JSr+xc
6OfzBznLdsH7vcJHgHzGWtI+fjXhUw+MqBtg5RM+Fj46IlSJ26MABbXTKwuZhUHy
pJfzsPehiRo9WgsyrgxlpsQ8VT8fEZN/0KPCh3jZS2VMHJ5fw6sr5mZYOKxmcaPf
hrv25mzCilcyCcmP2N8avIJV0UtNodSfmRffKNl2YkkWJrSHDGKG5KDoYHpnboTy
meWa4G3z84xSxMO11nUTpG4BYiW2Q4uqJRPQYpbn9nrb7QzXrgzQO6mntFMhDYC+
CwDjtPD0ysv18NZCcesUuLTBCk6KrunHSHx9SbKZkOelguY8KzCUKiJq1np86det
ixju1rfA+D+YrUTrZszrgKoJYceqgTtQLRzOCssJ/HSU3w02QQRv2hVSL85fDyve
WpP/19GcjEs=
=OFDc
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: openvswitch2.11 security update
Advisory ID:       RHSA-2021:0837-01
Product:           Fast Datapath
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0837
Issue date:        2021-03-15
CVE Names:         CVE-2020-27827 CVE-2020-35498 
=====================================================================

1. Summary:

An update for openvswitch2.11 is now available in Fast Datapath for Red Hat
Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Fast Datapath for Red Hat Enterprise Linux 8 - noarch, ppc64le, s390x, x86_64

3. Description:

Open vSwitch provides standard network bridging functions and support for
the OpenFlow protocol for remote per-flow control of traffic.

Security Fix(es):

* openvswitch: limitation in the OVS packet parsing in userspace leads to
DoS
(CVE-2020-35498)

* lldp/openvswitch: denial of service via externally triggered memory leak
(CVE-2020-27827)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1908845 - CVE-2020-35498 openvswitch: limitation in the OVS packet parsing in userspace leads to DoS
1921438 - CVE-2020-27827 lldp/openvswitch: denial of service via externally triggered memory leak

6. Package List:

Fast Datapath for Red Hat Enterprise Linux 8:

Source:
openvswitch2.11-2.11.3-83.el8fdp.src.rpm

noarch:
openvswitch2.11-test-2.11.3-83.el8fdp.noarch.rpm

ppc64le:
network-scripts-openvswitch2.11-2.11.3-83.el8fdp.ppc64le.rpm
openvswitch2.11-2.11.3-83.el8fdp.ppc64le.rpm
openvswitch2.11-debuginfo-2.11.3-83.el8fdp.ppc64le.rpm
openvswitch2.11-debugsource-2.11.3-83.el8fdp.ppc64le.rpm
openvswitch2.11-devel-2.11.3-83.el8fdp.ppc64le.rpm
python3-openvswitch2.11-2.11.3-83.el8fdp.ppc64le.rpm
python3-openvswitch2.11-debuginfo-2.11.3-83.el8fdp.ppc64le.rpm

s390x:
network-scripts-openvswitch2.11-2.11.3-83.el8fdp.s390x.rpm
openvswitch2.11-2.11.3-83.el8fdp.s390x.rpm
openvswitch2.11-debuginfo-2.11.3-83.el8fdp.s390x.rpm
openvswitch2.11-debugsource-2.11.3-83.el8fdp.s390x.rpm
openvswitch2.11-devel-2.11.3-83.el8fdp.s390x.rpm
python3-openvswitch2.11-2.11.3-83.el8fdp.s390x.rpm
python3-openvswitch2.11-debuginfo-2.11.3-83.el8fdp.s390x.rpm

x86_64:
network-scripts-openvswitch2.11-2.11.3-83.el8fdp.x86_64.rpm
openvswitch2.11-2.11.3-83.el8fdp.x86_64.rpm
openvswitch2.11-debuginfo-2.11.3-83.el8fdp.x86_64.rpm
openvswitch2.11-debugsource-2.11.3-83.el8fdp.x86_64.rpm
openvswitch2.11-devel-2.11.3-83.el8fdp.x86_64.rpm
python3-openvswitch2.11-2.11.3-83.el8fdp.x86_64.rpm
python3-openvswitch2.11-debuginfo-2.11.3-83.el8fdp.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-27827
https://access.redhat.com/security/cve/CVE-2020-35498
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYE9xOdzjgjWX9erEAQi/8Q/8CvM+H/StcBuPAmVQAY7JVm8pkf4JdX8j
STlwTLuvcoWEBUOChus7K68cC/VPHj5y3GEiujAxF9hx+EdeVR1HmC90/XVgrWAa
qQZzLnGxW+IsRkJ/wbYB37KU+OXFFAjNE2sO9WqPGoFbNQbpi0wuUyX8r3t8af+k
hnW/obtlW1Y6fVwt3u1yNDyPcReK3sSi5nv10w6bGOTqcCdva2n5nReddBlEPJpf
km19eN6E+lQxSrh1g6xKBBr8pPKFPCCj80we7KP3JFPAht4WRHxJEsXaBVCyv3qo
UVHQfSl30AVfE8MoBLcc2NG/Ys/rUd4TPt83ttHYVxpYuFQc/XWA0B7U59GUTZHZ
pLfhL1piKlok9fl0euyPXTjMJBUWh9PQmIT2NlisdjDwR3Hhxeh+3Q/DxBvEEBzN
UDovueQyL0NHa506VMMlTGLCmUbDv9h/UGOP2VslaUAmBcGsYkQaHk17XHkmGd7N
Ahp5S4nzj7NG/g5djYdEMaXtDrrWhrfc0oy00f6wQ/I6j/HlBN6S6nZjJ80x0Uop
UiJfiJ3aRrmDmua2X7x4k5/zUyy/9DIbpdKzGEjQPuG2YNTo8lbiRo5c1w/VtzhY
T60HGL0/JCqW/XiUkCljpUR32y8DPE38ZkMrl/NFsafA/flhzYzEe8jxNh+ImRML
dlxkXwSX8X0=
=pvQr
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: openvswitch2.13 security update
Advisory ID:       RHSA-2021:0835-01
Product:           Fast Datapath
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0835
Issue date:        2021-03-15
CVE Names:         CVE-2020-27827 CVE-2020-35498 
=====================================================================

1. Summary:

An update for openvswitch2.13 is now available in Fast Datapath for Red Hat
Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Fast Datapath for Red Hat Enterprise Linux 7 - noarch, ppc64le, s390x, x86_64

3. Description:

Open vSwitch provides standard network bridging functions and support for
the OpenFlow protocol for remote per-flow control of traffic.

Security Fix(es):

* openvswitch: limitation in the OVS packet parsing in userspace leads to
DoS (CVE-2020-35498)

* lldp/openvswitch: denial of service via externally triggered memory leak
(CVE-2020-27827)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1908845 - CVE-2020-35498 openvswitch: limitation in the OVS packet parsing in userspace leads to DoS
1921438 - CVE-2020-27827 lldp/openvswitch: denial of service via externally triggered memory leak

6. Package List:

Fast Datapath for Red Hat Enterprise Linux 7:

Source:
openvswitch2.13-2.13.0-81.el7fdp.src.rpm

noarch:
openvswitch2.13-test-2.13.0-81.el7fdp.noarch.rpm

ppc64le:
openvswitch2.13-2.13.0-81.el7fdp.ppc64le.rpm
openvswitch2.13-debuginfo-2.13.0-81.el7fdp.ppc64le.rpm
openvswitch2.13-devel-2.13.0-81.el7fdp.ppc64le.rpm
openvswitch2.13-ipsec-2.13.0-81.el7fdp.ppc64le.rpm
python3-openvswitch2.13-2.13.0-81.el7fdp.ppc64le.rpm

s390x:
openvswitch2.13-2.13.0-81.el7fdp.s390x.rpm
openvswitch2.13-debuginfo-2.13.0-81.el7fdp.s390x.rpm
openvswitch2.13-devel-2.13.0-81.el7fdp.s390x.rpm
openvswitch2.13-ipsec-2.13.0-81.el7fdp.s390x.rpm
python3-openvswitch2.13-2.13.0-81.el7fdp.s390x.rpm

x86_64:
openvswitch2.13-2.13.0-81.el7fdp.x86_64.rpm
openvswitch2.13-debuginfo-2.13.0-81.el7fdp.x86_64.rpm
openvswitch2.13-devel-2.13.0-81.el7fdp.x86_64.rpm
openvswitch2.13-ipsec-2.13.0-81.el7fdp.x86_64.rpm
python3-openvswitch2.13-2.13.0-81.el7fdp.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-27827
https://access.redhat.com/security/cve/CVE-2020-35498
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYE9xUtzjgjWX9erEAQjIMQ//ZwJVnyOEvinQ5yCE+9dYp8RNaVS4YzxI
Mf8ZdMDYoWXDq72enECN/XUWkJ4NTu1kdIYQqYIfS3nzDDNCHDsvJ2cxnjyIEMDc
RyRCpvSLws/iLnaHzU4cLZORrLxzNc6pZ9Kcm1Yi7SJrhSvVEtIF9JhQLgO/nFsL
jo6fgaA8PAfAOGg1/cN88giHrEz88XeMp0pTtcPNW6VuQbI1zGjsh4+m9DvfYsin
I9L8pa8rlmCkdr2huXesJD7LLEQ+Sk4lw1JfR1Cw/8ZrKqUU3OvjOzOVGooq5ANc
eLjXAeVcy+8D6l+88w6wgPZeSBv3rC4q/ze7tYTiQRHCI56cm2FRJpB3Hng1k3PV
49dR/PLMoDhswjCjfJRWn376lPUlHEyIdtRlHmgPTN7Pbp9QyMKXrwVMc9tbyQ+L
Laev6y2ACj1CDyLKO63KzkZIEH2Zs52rkpbk0mwFLKf5hM5S/L8MOhjBLNiAVBY9
xqLefW9RmhvDtF6Nad8LLZLDb7hBaTQu8kE2+uthm7P5ZvtVlnkJXpvyGPSWMecg
v0nCs1Exiuusd0Y7Zaa9uR/D3OFraNr+cvhf+dBOj+Ff9xH58WSl5ZoPCAmm+IkD
thPOLYGCWBpxRmTLtS/8IJR2TycdwpYMydi2WCwO52LtY076/QDxbAxwe1tDBU3Y
6j7JgB7G8jw=
=y4Ny
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYE/rGuNLKJtyKPYoAQjpMw//bM3CbL8gpGOlki1FeVr1xzLlcebUbA3R
Xax6N+w9jYxgAtVjnWXgIrm3rHw8G0Mf1oeqQwWaCNnuko6UMo7gxk+QTgjaUurc
CuGRsaTElP/X5fn8ocKBVI2NF31OPTU5RDjNUhhS3V6KViOY/IWQNSpTKQHLoHvF
k9A004eO9340Ec3a/tn24xIbcG5h6Azv1nfHcOteXY6FP1NHQrLDYEPE+pYIpUpC
ZNi3EI6P+t2fe75F1SbuuY4DkEYh5kCxw8uX75+D1CJQKFz6UJ99qaLTbXOUB+87
vH7BRlfNCyY6pLoZAxWY/aGgm52N/O90jEkQlZqqfvvrBtI5Jz2Xcp866JDVYHEI
GaN+RZXoDWlFfrfatVK1M0+gc28+lxbqDSnSft2X+nP2muAHFbMia14FPl/MQG+h
xARKhoaUV0CvuZnfLWkMllhSZw6S6Vci4ArsM4A5x535aFIsnEiO3nXxuiebZFXG
T9D4vfV2lABjkapNq+RWemnFi3ignAK0WIiUtn+ahNDTQJE33E8TrYHfB2nxsaCz
qo1hQ8hweZ02hZu2C+o/cr1pdpGc70ABNUvgy3fjye/Nw2p30c0gdnxKHniaraz3
TfrAe3V9CS+YZwPYOSTnyTSd95GkdBdJpticxj7dwb91jMd9MAs8IU7QL1pZDSK6
vYgXraOds2w=
=coA4
-----END PGP SIGNATURE-----