Bugzilla – Bug 1219465
VUL-0: CVE-2023-3966: openvswitch, openvswitch3: Invalid memory access in Geneve with HW offload
Last modified: 2024-07-12 16:31:17 UTC
Affected: - SUSE:SLE-15-SP2:Update/openvswitch - SUSE:SLE-15-SP3:Update/openvswitch - SUSE:SLE-15-SP4:Update/openvswitch - SUSE:SLE-15-SP5:Update/openvswitch3 CRD is tomorrow, could we please prioritize this?
is public OSS:2024/Q1/118: https://seclists.org/oss-sec/2024/q1/118
SUSE-SU-2024:0738-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1219465 CVE References: CVE-2023-3966 Sources used: openSUSE Leap 15.5 (src): openvswitch3-3.1.0-150500.3.16.1 SUSE Linux Enterprise Micro 5.5 (src): openvswitch3-3.1.0-150500.3.16.1 Server Applications Module 15-SP5 (src): openvswitch3-3.1.0-150500.3.16.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Hello, The patch is not available to the below distributions since they are < 2.17.x where the fix is available, - SUSE:SLE-15-SP2:Update/openvswitch - SUSE:SLE-15-SP3:Update/openvswitch - SUSE:SLE-15-SP4:Update/openvswitch Recreating the patch on older source code may trigger regressions as some code is not available in the older versions. It is better that we upgrade the OVS version in this distributions to mitigate the vulnerability.
(In reply to Duraisankar P from comment #8) > Hello, > > The patch is not available to the below distributions since they are < > 2.17.x where the fix is available, > > - SUSE:SLE-15-SP2:Update/openvswitch > - SUSE:SLE-15-SP3:Update/openvswitch > - SUSE:SLE-15-SP4:Update/openvswitch > > Recreating the patch on older source code may trigger regressions as some > code is not available in the older versions. > > It is better that we upgrade the OVS version in this distributions to > mitigate the vulnerability. Hi, thanks for checking. The 2.17 patch seems to apply quite well to 2.13 and 2.14. Can you double check please?
SUSE-SU-2024:0912-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1219465 CVE References: CVE-2023-3966 Sources used: SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): openvswitch-2.13.2-150200.9.34.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): openvswitch-2.13.2-150200.9.34.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): openvswitch-2.13.2-150200.9.34.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:0937-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1219465 CVE References: CVE-2023-3966 Maintenance Incident: [SUSE:Maintenance:32940](https://smelt.suse.de/incident/32940/) Sources used: openSUSE Leap 15.4 (src): openvswitch-2.14.2-150400.24.23.1 openSUSE Leap 15.5 (src): openvswitch-2.14.2-150400.24.23.1 Legacy Module 15-SP5 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Package Hub 15 15-SP5 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Manager Proxy 4.3 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Manager Retail Branch Server 4.3 (src): openvswitch-2.14.2-150400.24.23.1 SUSE Manager Server 4.3 (src): openvswitch-2.14.2-150400.24.23.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:0922-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1219465 CVE References: CVE-2023-3966 Maintenance Incident: [SUSE:Maintenance:32964](https://smelt.suse.de/incident/32964/) Sources used: openSUSE Leap 15.3 (src): openvswitch-2.14.2-150300.19.20.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): openvswitch-2.14.2-150300.19.20.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): openvswitch-2.14.2-150300.19.20.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): openvswitch-2.14.2-150300.19.20.1 SUSE Enterprise Storage 7.1 (src): openvswitch-2.14.2-150300.19.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Hello, Can we close this ticket since the backport is completed for all the affected distributions ?
Done, closing.
SUSE-SU-2024:0738-2: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1219465 CVE References: CVE-2023-3966 Maintenance Incident: [SUSE:Maintenance:32619](https://smelt.suse.de/incident/32619/) Sources used: SUSE Linux Enterprise Micro 5.5 (src): openvswitch3-3.1.0-150500.3.16.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.