Publishing details

Changelog

openvswitch (2.13.8-0ubuntu1.4) focal-security; urgency=medium

  * SECURITY UPDATE: Incomplete fix for CVE-2023-5366
    - debian/patches/CVE-2023-5366-2.patch: follow Open Flow spec
      converting from OF to DP in lib/odp-util.c, tests/ofproto-macros.at,
      tests/system-traffic.at.
    - CVE-2023-5366
  * SECURITY UPDATE: vulnerable to crafted Geneve packets
    - debian/patches/CVE-2023-3966.patch: check geneve metadata length in
      lib/netdev-offload-tc.c, tests/system-offloads-traffic.at.
    - CVE-2023-3966

 -- Marc Deslauriers <email address hidden>  Fri, 01 Mar 2024 12:59:59 -0500

Available diffs

Builds

Built packages

Package files