Vulnerability CVE-2021-36980: Information

Description

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Published: July 20, 2021
Modified: Nov. 26, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
openvswitchsisyphus2.16.1-alt23.3.0-alt1ALT-PU-2021-3392-1290487Fixed
openvswitchsisyphus_e2k2.16.1-alt23.3.0-alt1ALT-PU-2021-4833-1-Fixed
openvswitchsisyphus_riscv642.16.1-alt23.3.0-alt1ALT-PU-2021-4470-1-Fixed
openvswitchp102.16.1-alt22.17.9-alt1ALT-PU-2021-3569-1290982Fixed
openvswitchp10_e2k2.16.1-alt22.17.9-alt1ALT-PU-2021-4654-1-Fixed
openvswitchc10f12.16.1-alt22.17.6-alt1ALT-PU-2021-3569-1290982Fixed
openvswitchp112.16.1-alt23.3.0-alt1ALT-PU-2021-3392-1290487Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
      Start including
      2.11.0
      End including
      2.15.0