Bug 1188524 (CVE-2021-36980) - VUL-0: CVE-2021-36980: openvswitch: use-after-free in decode_NXAST_RAW_ENCAP
Summary: VUL-0: CVE-2021-36980: openvswitch: use-after-free in decode_NXAST_RAW_ENCAP
Status: RESOLVED FIXED
: 1196498 (view as bug list)
Alias: CVE-2021-36980
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/304595/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-36980:5.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2021-07-20 14:34 UTC by Alexander Bergmann
Modified: 2024-07-26 10:21 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2022-02-25 13:25:03 UTC
*** Bug 1196498 has been marked as a duplicate of this bug. ***
Comment 2 Marcus Meissner 2022-02-25 13:25:40 UTC
ping? any update
Comment 3 Carlos López 2022-08-12 11:39:49 UTC
Apparently Jaime no longer maintains this, so reassigning to coldpool. Could someone from the list pick it up? It is long overdue.
Comment 4 Petr Gajdos 2022-08-24 09:56:31 UTC
Submitted where the code have been found: 
15sp4,15sp3,15sp2,15sp1,15,12sp5,12sp4/openvswitch

TW/openvswitch already fixed by a version update.

I believe all fixed.
Comment 6 Carlos López 2022-08-24 11:04:38 UTC
(In reply to Petr Gajdos from comment #4)
> Submitted where the code have been found: 
> 15sp4,15sp3,15sp2,15sp1,15,12sp5,12sp4/openvswitch
> 
> TW/openvswitch already fixed by a version update.
> 
> I believe all fixed.

Our tracking also has these as affected, but based on version numbers I'd say they are not.
- SUSE:SLE-12-SP2:Update
- SUSE:SLE-12-SP3:Update

Could you verify this? Thanks!
Comment 7 Petr Gajdos 2022-08-24 11:50:40 UTC
(In reply to Carlos López from comment #6)

> Our tracking also has these as affected, but based on version numbers I'd
> say they are not.
> - SUSE:SLE-12-SP2:Update
> - SUSE:SLE-12-SP3:Update
> 
> Could you verify this? Thanks!

I have verified there's no decode_NXAST_RAW_ENCAP().
Comment 8 Swamp Workflow Management 2022-09-06 10:30:08 UTC
SUSE-SU-2022:3096-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1188524
CVE References: CVE-2021-36980
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    openvswitch-2.13.2-150200.9.17.1
openSUSE Leap 15.3 (src):    openvswitch-2.13.2-150200.9.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2022-09-06 13:24:44 UTC
SUSE-SU-2022:3098-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1188524
CVE References: CVE-2021-36980
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    openvswitch-2.11.5-3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2022-09-06 13:27:26 UTC
SUSE-SU-2022:3099-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1188524
CVE References: CVE-2021-36980
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    openvswitch-2.14.2-150400.24.3.1
SUSE Linux Enterprise Module for Server Applications 15-SP4 (src):    openvswitch-2.14.2-150400.24.3.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    openvswitch-2.14.2-150400.24.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-09-06 16:21:29 UTC
SUSE-SU-2022:3116-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1188524
CVE References: CVE-2021-36980
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    openvswitch-2.14.2-150300.19.3.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    openvswitch-2.14.2-150300.19.3.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    openvswitch-2.14.2-150300.19.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Maintenance Automation 2023-04-07 12:30:03 UTC
SUSE-SU-2023:1795-1: An update that solves two vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1188524, 1203865
CVE References: CVE-2021-36980, CVE-2022-32166
Sources used:
openSUSE Leap 15.4 (src): openvswitch-2.11.5-150100.3.18.2, dpdk-18.11.9-150100.4.23.1
SUSE Package Hub 15 15-SP4 (src): openvswitch-2.11.5-150100.3.18.2, dpdk-18.11.9-150100.4.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Maintenance Automation 2023-06-02 12:30:02 UTC
SUSE-SU-2023:2360-1: An update that solves four vulnerabilities can now be installed.

Category: security (important)
Bug References: 1188524, 1203865, 1206580, 1206581
CVE References: CVE-2021-36980, CVE-2022-32166, CVE-2022-4337, CVE-2022-4338
Sources used:
SUSE OpenStack Cloud 9 (src): openvswitch-2.8.10-4.33.1
SUSE OpenStack Cloud Crowbar 9 (src): openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4 (src): openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (src): openvswitch-2.8.10-4.33.1
SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (src): openvswitch-2.8.10-4.33.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Andrea Mattiazzo 2024-07-26 10:21:53 UTC
All done, closing.