[USN-5065-1] Open vSwitch vulnerability

========================================================================== Ubuntu Security Notice USN-5065-1 September 08, 2021
openvswitch vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 21.04 – Ubuntu 20.04 LTS
Summary:
Open vSwitch could be made to crash or run programs if it received specially crafted network traffic.
Software Description: – openvswitch: Ethernet virtual switch
Details:
It was discovered that Open vSwitch incorrectly handled decoding RAW_ENCAP actions. A remote attacker could use this issue to cause Open vSwitch to crash, resulting in a denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 21.04: openvswitch-common 2.15.0-0ubuntu3.1
Ubuntu 20.04 LTS: openvswitch-common 2.13.3-0ubuntu0.20.04.2
In general, a standard system update will make all the necessary changes.
References: ubuntu.com/security/notices/USN-5065-1 CVE-2021-36980
Package Information: launchpad.net/ubuntu/+source/openvswitch/2.15.0-0ubuntu3.1 launchpad.net/ubuntu/+source/openvswitch/2.13.3-0ubuntu0.20.04.2