Bug 1219465 (CVE-2023-3966)

Summary: VUL-0: CVE-2023-3966: openvswitch, openvswitch3: Invalid memory access in Geneve with HW offload
Product: [Novell Products] SUSE Security Incidents Reporter: Thomas Leroy <thomas.leroy>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: bindu.tg, carlos.lopez, Duraisankar.pitchumani, meissner, stefan.fent
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/392844/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-3966:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 3 Thomas Leroy 2024-02-07 09:01:47 UTC
Affected:
- SUSE:SLE-15-SP2:Update/openvswitch
- SUSE:SLE-15-SP3:Update/openvswitch
- SUSE:SLE-15-SP4:Update/openvswitch
- SUSE:SLE-15-SP5:Update/openvswitch3

CRD is tomorrow, could we please prioritize this?
Comment 4 Marcus Meissner 2024-02-09 08:01:26 UTC
is public

        OSS:2024/Q1/118: https://seclists.org/oss-sec/2024/q1/118
Comment 7 Maintenance Automation 2024-03-01 12:30:03 UTC
SUSE-SU-2024:0738-1: An update that solves one vulnerability can now be installed.

Category: security (important)
Bug References: 1219465
CVE References: CVE-2023-3966
Sources used:
openSUSE Leap 15.5 (src): openvswitch3-3.1.0-150500.3.16.1
SUSE Linux Enterprise Micro 5.5 (src): openvswitch3-3.1.0-150500.3.16.1
Server Applications Module 15-SP5 (src): openvswitch3-3.1.0-150500.3.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Duraisankar P 2024-03-11 08:48:26 UTC
Hello, 

The patch is not available to the below distributions since they are < 2.17.x where the fix is available, 

- SUSE:SLE-15-SP2:Update/openvswitch
- SUSE:SLE-15-SP3:Update/openvswitch
- SUSE:SLE-15-SP4:Update/openvswitch

Recreating the patch on older source code may trigger regressions as some code is not available in the older versions. 

It is better that we upgrade the OVS version in this distributions to mitigate the vulnerability.
Comment 9 Thomas Leroy 2024-03-11 09:28:01 UTC
(In reply to Duraisankar P from comment #8)
> Hello, 
> 
> The patch is not available to the below distributions since they are <
> 2.17.x where the fix is available, 
> 
> - SUSE:SLE-15-SP2:Update/openvswitch
> - SUSE:SLE-15-SP3:Update/openvswitch
> - SUSE:SLE-15-SP4:Update/openvswitch
> 
> Recreating the patch on older source code may trigger regressions as some
> code is not available in the older versions. 
> 
> It is better that we upgrade the OVS version in this distributions to
> mitigate the vulnerability.

Hi, thanks for checking. The 2.17 patch seems to apply quite well to 2.13 and 2.14. Can you double check please?
Comment 13 Maintenance Automation 2024-03-18 08:30:09 UTC
SUSE-SU-2024:0912-1: An update that solves one vulnerability can now be installed.

Category: security (important)
Bug References: 1219465
CVE References: CVE-2023-3966
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): openvswitch-2.13.2-150200.9.34.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): openvswitch-2.13.2-150200.9.34.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): openvswitch-2.13.2-150200.9.34.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Maintenance Automation 2024-03-22 12:31:33 UTC
SUSE-SU-2024:0937-1: An update that solves one vulnerability can now be installed.

Category: security (important)
Bug References: 1219465
CVE References: CVE-2023-3966
Maintenance Incident: [SUSE:Maintenance:32940](https://smelt.suse.de/incident/32940/)
Sources used:
openSUSE Leap 15.4 (src):
 openvswitch-2.14.2-150400.24.23.1
openSUSE Leap 15.5 (src):
 openvswitch-2.14.2-150400.24.23.1
Legacy Module 15-SP5 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Package Hub 15 15-SP5 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Manager Proxy 4.3 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Manager Retail Branch Server 4.3 (src):
 openvswitch-2.14.2-150400.24.23.1
SUSE Manager Server 4.3 (src):
 openvswitch-2.14.2-150400.24.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Maintenance Automation 2024-03-22 12:32:31 UTC
SUSE-SU-2024:0922-1: An update that solves one vulnerability can now be installed.

Category: security (important)
Bug References: 1219465
CVE References: CVE-2023-3966
Maintenance Incident: [SUSE:Maintenance:32964](https://smelt.suse.de/incident/32964/)
Sources used:
openSUSE Leap 15.3 (src):
 openvswitch-2.14.2-150300.19.20.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 openvswitch-2.14.2-150300.19.20.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src):
 openvswitch-2.14.2-150300.19.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 openvswitch-2.14.2-150300.19.20.1
SUSE Enterprise Storage 7.1 (src):
 openvswitch-2.14.2-150300.19.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Duraisankar P 2024-03-28 05:54:39 UTC
Hello, 

Can we close this ticket since the backport is completed for all the affected distributions ?
Comment 18 Carlos López 2024-04-19 09:13:17 UTC
Done, closing.
Comment 19 Maintenance Automation 2024-07-12 16:31:17 UTC
SUSE-SU-2024:0738-2: An update that solves one vulnerability can now be installed.

Category: security (important)
Bug References: 1219465
CVE References: CVE-2023-3966
Maintenance Incident: [SUSE:Maintenance:32619](https://smelt.suse.de/incident/32619/)
Sources used:
SUSE Linux Enterprise Micro 5.5 (src):
 openvswitch3-3.1.0-150500.3.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.