UbuntuUpdates.org

Package "ovn-controller-vtep"

Name: ovn-controller-vtep

Description:

OVN vtep controller

Latest version: 20.03.2-0ubuntu0.20.04.6
Release: focal (20.04)
Level: security
Repository: universe
Head package: ovn
Homepage: https://github.com/ovn-org/ovn

Links


Download "ovn-controller-vtep"


Other versions of "ovn-controller-vtep" in Focal

Repository Area Version
base universe 20.03.0-0ubuntu1
updates universe 20.03.2-0ubuntu0.20.04.6

Changelog

Version: 20.03.2-0ubuntu0.20.04.6 2025-03-31 16:07:20 UTC

  ovn (20.03.2-0ubuntu0.20.04.6) focal-security; urgency=medium

  * SECURITY UPDATE: ACL bypass in logical switch with DNS records
    - debian/patches/CVE-2025-0650.patch: skip only OVN DNS responder
      packets from OUT_ACL in controller/pinctrl.c,
      include/ovn/logical-fields.h, lib/logical-fields.c,
      northd/ovn-northd.c, tests/ovn.at.
    - CVE-2025-0650

 -- Marc Deslauriers <email address hidden> Fri, 31 Jan 2025 11:36:29 -0500

Source diff to previous version
CVE-2025-0650 A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations

Version: 20.03.2-0ubuntu0.20.04.5 2024-03-12 16:07:13 UTC

  ovn (20.03.2-0ubuntu0.20.04.5) focal-security; urgency=medium

  * SECURITY UPDATE: Insufficient validation of incoming BFD packets
    - debian/patches/CVE-2024-2182.patch: set check_tnl_key for BFD on
      tunnel ifaces in controller/bfd.c, tests/ovn.at.
    - CVE-2024-2182

 -- Marc Deslauriers <email address hidden> Fri, 08 Mar 2024 19:47:13 -0500




About   -   Send Feedback to @ubuntu_updates