Bug 2019692 (CVE-2021-3905)

Summary: CVE-2021-3905 openvswitch: External triggered memory leak in Open vSwitch while processing fragmented packets
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aconole, apevec, bmontgom, chrisw, ctrautma, dbecker, eparis, fleitner, jburrell, jhsiao, jjoyce, jschluet, lhh, lpeer, mburns, michal.skrivanek, mperina, nstielau, ovs-qe, ovs-team, ralongi, rhos-maint, rkhan, sclewis, slinaber, sponnaga, tgraf, tredaelli, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openvswitch 2.12 Doc Type: If docs needed, set a value
Doc Text:
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2019693, 2021652, 2021653, 2021654, 2021655, 2021656, 2021657, 2021658, 2022491, 2022492, 2022493, 2022494, 2022495, 2023644, 2023956, 2025200, 2025201, 2025578    
Bug Blocks: 2014937    

Description Dhananjay Arunesh 2021-11-03 07:28:55 UTC
A vulnerability was found in Openvswitch where a memory leak exists during userspace ip fragmentation processing which causes OpenvSwitch to leak packet buffers.

References:
https://github.com/openvswitch/ovs-issues/issues/226

Comment 1 Dhananjay Arunesh 2021-11-03 07:29:21 UTC
Created openvswitch tracking bugs for this issue:

Affects: fedora-all [bug 2019693]

Comment 2 Mauro Matteo Cascella 2021-11-05 18:48:49 UTC
Upstream commit:
https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349