Due to a limitation in the OVS packet parsing in userspace, the resulting megaflow in the kernel is too wide which can potentially cause a DoS.
Acknowledgments: Name: Joakim Hindersson <joakim.hindersson>
Created openvswitch tracking bugs for this issue: Affects: fedora-all [bug 1927492] Affects: openstack-rdo [bug 1927493]
External References: https://www.openwall.com/lists/oss-security/2021/02/10/4
Upstream Commits: * master https://github.com/openvswitch/ovs/commit/79349cbab0b2a755140eedb91833ad2760520a83 * 2.15 https://github.com/openvswitch/ovs/commit/0625dc79aec73b966f206e55655a2816696246d0 * 2.14 https://github.com/openvswitch/ovs/commit/59b588604b89e85b463984ba08a99badb4fcba15 * 2.13 https://github.com/openvswitch/ovs/commit/3512fb512c76a1f08eba4005aa2eb69160d0840e * 2.12 https://github.com/openvswitch/ovs/commit/53c1b8b166f3dd217bc391d707885f789e9ecc49 * 2.11 https://github.com/openvswitch/ovs/commit/abd7a457652e6734902720fe6a5dddb3fc0d1e3b * 2.10 https://github.com/openvswitch/ovs/commit/79cec1a736b91548ec882d840986a11affda1068 * 2.9 https://github.com/openvswitch/ovs/commit/48ceca0446b1c2c2c03e7551048c5b19ed23cc97 * 2.8 https://github.com/openvswitch/ovs/commit/35c280072c1c3ed58202745b7d27fbbd0736999b * 2.7 https://github.com/openvswitch/ovs/commit/ad0d22f6435b43ecfc30c0e877d490d36721f200 * 2.6 https://github.com/openvswitch/ovs/commit/673c08eee8c8d4f2999ddd31524de7ff0f72b559 * 2.5 https://github.com/openvswitch/ovs/commit/354e7d860e444fd1472541b0fdc3b8678aa74828
Statement: Red Hat OpenStack Platform 13's openvswitch package will receive it's fixes from Fast Datapath.
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 8 Via RHSA-2021:0497 https://access.redhat.com/errata/RHSA-2021:0497
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-35498
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 8 Via RHSA-2021:0837 https://access.redhat.com/errata/RHSA-2021:0837
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 7 Via RHSA-2021:0834 https://access.redhat.com/errata/RHSA-2021:0834
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 7 Via RHSA-2021:0835 https://access.redhat.com/errata/RHSA-2021:0835
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Via RHSA-2021:1050 https://access.redhat.com/errata/RHSA-2021:1050
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 7 Via RHSA-2021:2077 https://access.redhat.com/errata/RHSA-2021:2077
This issue has been addressed in the following products: Red Hat OpenStack Platform 13.0 (Queens) Via RHSA-2021:2456 https://access.redhat.com/errata/RHSA-2021:2456