Use-after-free in Open vSwitch - CVE-2021-36980
Published: July 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action. A remote attacker can send a specially crafted request to the system, trigger a use-after-free error and execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
toolbox (Red Hat package)
coreos-installer (Red Hat package)
butane (Red Hat package)
console-login-helper-messages (Red Hat package)
python-eventlet (Red Hat package)
python-hardware (Red Hat package)
ignition (Red Hat package)
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
python-sushy-oem-idrac (Red Hat package)
kata-containers (Red Hat package)
python-ironic-prometheus-exporter (Red Hat package)
haproxy (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.15 (Red Hat package)
jenkins (Red Hat package)
python-sushy (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
python-ironic-lib (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
rust-afterburn (Red Hat package)
openstack-ironic-inspector (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
ironic-images (Red Hat package)
python-wcwidth (Red Hat package)
rust-bootupd (Red Hat package)
python-scciclient (Red Hat package)
python-cmd2 (Red Hat package)
python-pyperclip (Red Hat package)
python-pycdlib (Red Hat package)
python-osc-lib (Red Hat package)
libopenvswitch-2_8-0-debuginfo
libopenvswitch-2_8-0
openvswitch-debugsource
openvswitch
openvswitch-debuginfo
libopenvswitch-2_11-0
libopenvswitch-2_11-0-debuginfo
openvswitch-ovn-docker
openvswitch-ovn-host
openvswitch-ovn-host-debuginfo
openvswitch-ovn-vtep
openvswitch-ovn-vtep-debuginfo
openvswitch-ovn-common
openvswitch-ovn-central
openvswitch-ovn-central-debuginfo
python3-ovs-debuginfo
openvswitch-ovn-common-debuginfo
openvswitch-devel
openvswitch-help
openvswitch2.13 (Red Hat package)
libopenvswitch-2_13-0-debuginfo
libopenvswitch-2_13-0
openvswitch-common (Ubuntu package)
python3-ovs
libopenvswitch-2_14-0-debuginfo
libopenvswitch-2_14-0
openvswitch-ipsec
openvswitch-pki
openvswitch-test
openvswitch-test-debuginfo
openvswitch-vtep
openvswitch-vtep-debuginfo
openvswitch-doc
openvswitch2.16 (Red Hat package)
net-misc/openvswitch
python-cliff (Red Hat package)
python-ironicclient (Red Hat package)
python-dracclient (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
openstack-ironic (Red Hat package)
libdpdk-18_11-debuginfo
libdpdk-18_11
libovn-20_03-0
libovn-20_03-0-debuginfo
ovn-debuginfo
libovn-20_06-0-debuginfo
ovn-central-debuginfo
ovn-devel
ovn-docker
ovn-host
ovn-host-debuginfo
ovn-vtep
ovn-vtep-debuginfo
ovn-central
ovn
ovn-doc
libovn-20_06-0
ovn21.09 (Red Hat package)
redhat-release-coreos (Red Hat package)
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenShift Container Platform
How to mitigate CVE-2021-36980
toolbox (Red Hat package) - update to 0.0.8-3.rhaos4.9.el8
coreos-installer (Red Hat package) - update to 0.10.0-2.rhaos4.9.el8
butane (Red Hat package) - update to 0.13.1-1.rhaos4.9.el8
console-login-helper-messages (Red Hat package) - update to 0.20.3-1.rhaos4.9.el8
python-eventlet (Red Hat package) - update to 0.30.2-1.el8
python-hardware (Red Hat package) - update to 0.28.0-0.20210719162211.96c9863.el8
ignition (Red Hat package) - update to 2.12.0-1.rhaos4.9.el8
runc (Red Hat package) - update to 1.0.1-2.rhaos4.9.git4144b63.el8
cri-tools (Red Hat package) - update to 1.22.0-1.el8
cri-o (Red Hat package) - update to 1.22.0-73.rhaos4.9.gitbdf286c.el8
python-sushy-oem-idrac (Red Hat package) - update to 2.0.1-0.20210326153413.83b7eb0.el8
kata-containers (Red Hat package) - update to 2.1.0-6.el8
python-ironic-prometheus-exporter (Red Hat package) - update to 2.3.0-0.20210611093526.3c9b517.el8
haproxy (Red Hat package) - update to 2.2.15-1.el8
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-86.el8fdp, 2.11.3-89.el7fdp
openvswitch2.15 (Red Hat package) - addressed in versions 2.15.0-24.el8fdp, 2.15.0-28.el8fdp
jenkins (Red Hat package) - update to 2.289.3.1630554997-1.el8
python-sushy (Red Hat package) - update to 3.11.0-0.20210802160404.b93dcba.el8
openshift (Red Hat package) - update to 4.9.0-202110080828.p0.git.894a78b.assembly.stream.el8
openshift-clients (Red Hat package) - update to 4.9.0-202109101042.p0.git.96e95ce.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.9.0-202109101042.p0.git.e66f211.assembly.stream.el8
python-ironic-lib (Red Hat package) - update to 4.7.2-0.20210707162243.d33cf3e.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.9.0-202109101042.p0.git.39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.9.1630555871-1.el8
rust-afterburn (Red Hat package) - update to 5.1.0-1.rhaos4.9.el8
openstack-ironic-inspector (Red Hat package) - update to 10.7.1-0.20210722154052.edf655c.el8
ironic-images (Red Hat package) - update to 2021.2-20210827.1.el8
python-wcwidth (Red Hat package) - update to 0.1.7-14.el8ost
rust-bootupd (Red Hat package) - update to 0.2.5-3.rhaos4.9.el8
python-scciclient (Red Hat package) - update to 0.9.1-0.20210720102209.34ccd96.el8
python-cmd2 (Red Hat package) - update to 1.4.0-1.1.el8
python-pyperclip (Red Hat package) - update to 1.6.4-6.el8ost
python-pycdlib (Red Hat package) - update to 1.11.0-3.el8
python-osc-lib (Red Hat package) - update to 2.3.1-0.20210318171847.2b7a679.el8
libopenvswitch-2_8-0-debuginfo - update to 2.8.10-4.33.1
libopenvswitch-2_8-0 - update to 2.8.10-4.33.1
openvswitch-debugsource - addressed in versions 2.8.10-4.33.1, 2.11.5-3.6.1, 2.11.5-150100.3.18.2, 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch - addressed in versions 2.8.10-4.33.1, 2.11.5-3.6.1, 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-debuginfo - addressed in versions 2.8.10-4.33.1, 2.11.5-3.6.1, 2.11.5-150100.3.18.2, 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
libopenvswitch-2_11-0 - addressed in versions 2.11.5-3.6.1, 2.11.5-150100.3.18.2
libopenvswitch-2_11-0-debuginfo - addressed in versions 2.11.5-3.6.1, 2.11.5-150100.3.18.2
openvswitch-ovn-docker - update to 2.11.5-150100.3.18.2
openvswitch-ovn-host - update to 2.11.5-150100.3.18.2
openvswitch-ovn-host-debuginfo - update to 2.11.5-150100.3.18.2
openvswitch-ovn-vtep - update to 2.11.5-150100.3.18.2
openvswitch-ovn-vtep-debuginfo - update to 2.11.5-150100.3.18.2
openvswitch-ovn-common - update to 2.11.5-150100.3.18.2
openvswitch-ovn-central - update to 2.11.5-150100.3.18.2
openvswitch-ovn-central-debuginfo - update to 2.11.5-150100.3.18.2
python3-ovs-debuginfo - update to 2.11.5-150100.3.18.2
openvswitch-ovn-common-debuginfo - update to 2.11.5-150100.3.18.2
openvswitch-debuginfo - update to 2.12.0-12
openvswitch-debugsource - update to 2.12.0-12
openvswitch-devel - update to 2.12.0-12
openvswitch-help - update to 2.12.0-12
openvswitch - update to 2.12.0-12
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-102.el7fdp, 2.13.0-114.el8fdp
libopenvswitch-2_13-0-debuginfo - update to 2.13.2-150200.9.17.1
libopenvswitch-2_13-0 - update to 2.13.2-150200.9.17.1
openvswitch-common (Ubuntu package) - addressed in versions 2.13.3-0ubuntu0.20.04.2, 2.15.0-0ubuntu3.1
python3-ovs - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
libopenvswitch-2_14-0-debuginfo - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
libopenvswitch-2_14-0 - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-devel - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-ipsec - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-pki - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-test - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-test-debuginfo - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-vtep - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-vtep-debuginfo - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch-doc - addressed in versions 2.14.2-150300.19.3.1, 2.14.2-150400.24.3.1
openvswitch2.16 (Red Hat package) - update to 2.16.0-15.el8fdp
net-misc/openvswitch - update to 2.17.6
python-cliff (Red Hat package) - update to 3.7.0-0.20210318182629.117a100.el8
python-ironicclient (Red Hat package) - update to 4.7.1-0.20210611202214.3d146fb.el8
Red Hat OpenShift Container Platform - update to 4.9.0
python-dracclient (Red Hat package) - update to 5.1.1-0.20210318155434.98c7ea3.el8
openstack-ironic-python-agent (Red Hat package) - update to 8.1.1-0.20210722155129.7f3de67.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20210812092216.4aec741.el8
libdpdk-18_11-debuginfo - update to 18.11.9-150100.4.23.1
libdpdk-18_11 - update to 18.11.9-150100.4.23.1
libovn-20_03-0 - update to 20.03.1-150200.9.17.1
libovn-20_03-0-debuginfo - update to 20.03.1-150200.9.17.1
ovn-debuginfo - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
libovn-20_06-0-debuginfo - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-central-debuginfo - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-devel - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-docker - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-host - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-host-debuginfo - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-vtep - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-vtep-debuginfo - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-central - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn-doc - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
libovn-20_06-0 - addressed in versions 20.06.2-150300.19.3.1, 20.06.2-150400.24.3.1
ovn21.09 (Red Hat package) - update to 21.09.0-20.el8fdp
redhat-release-coreos (Red Hat package) - update to 49.84-2.el8
External References
Related Security Bulletins
- Use-after-free in Open vSwitch
- Arch Linux update for openvswitch
- Red Hat Virtualization update for openvswitch2.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.9
- Ubuntu update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.15
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.11
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.11
- SUSE update for openvswitch
- SUSE update for openvswitch
- Gentoo update for Open vSwitch
- openEuler update for openvswitch