ALT-BU-2023-3330-1
Branch sisyphus update bulletin.
Package alterator-setup updated to version 0.3.16-alt1 for branch sisyphus in task 319722.
Closed bugs
После установки на плату без видеокарты не запускается X
Package kernel-image-centos updated to version 5.14.0.307-alt1.el9 for branch sisyphus in task 319780.
Closed vulnerabilities
BDU:2023-01795
Уязвимость сервера NFS (Network File System) ядра операционной системы Linux, позволяющая нарушителю получить доступ к защищаемой информации или вызвать отказ в обслуживании
Modified: 2025-02-18
CVE-2023-1652
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
Package make-initrd-bootchain updated to version 0.1.5-alt14 for branch sisyphus in task 319732.
Closed bugs
Не загружаются iso с plymouth, если в cmdline указать console=ttyS0 или console=tty0
Closed vulnerabilities
Modified: 2025-02-18
CVE-2023-26916
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.
- https://github.com/CESNET/libyang/issues/1979
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6NQZHCJG3SBMFOQNIPRZGKDK3ARHLTTB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2VWGCMYKQH4BTFEHX5VYEXXOPIKKFHS/
- https://github.com/CESNET/libyang/issues/1979
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6NQZHCJG3SBMFOQNIPRZGKDK3ARHLTTB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2VWGCMYKQH4BTFEHX5VYEXXOPIKKFHS/
Modified: 2025-02-11
CVE-2023-26917
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2023-31489
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
- https://github.com/FRRouting/frr/issues/13098
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/
- https://github.com/FRRouting/frr/issues/13098
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/
Modified: 2024-11-21
CVE-2023-31490
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
- https://github.com/FRRouting/frr/issues/13099
- https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/
- https://www.debian.org/security/2023/dsa-5495
- https://github.com/FRRouting/frr/issues/13099
- https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/
- https://www.debian.org/security/2023/dsa-5495
Closed vulnerabilities
BDU:2022-05391
Уязвимость драйвера mlx5 набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая науршителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-2132
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
- https://bugs.dpdk.org/show_bug.cgi?id=1031
- https://bugzilla.redhat.com/show_bug.cgi?id=2099475
- https://lists.debian.org/debian-lts-announce/2022/09/msg00000.html
- https://bugs.dpdk.org/show_bug.cgi?id=1031
- https://bugzilla.redhat.com/show_bug.cgi?id=2099475
- https://lists.debian.org/debian-lts-announce/2022/09/msg00000.html
Modified: 2024-11-21
CVE-2022-28199
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
- http://www.openwall.com/lists/oss-security/2022/09/06/2
- https://nvidia.custhelp.com/app/answers/detail/a_id/5389
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
- http://www.openwall.com/lists/oss-security/2022/09/06/2
- https://nvidia.custhelp.com/app/answers/detail/a_id/5389
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
Package openvswitch updated to version 2.17.6-alt1 for branch sisyphus in task 319807.
Closed vulnerabilities
BDU:2023-00290
Уязвимость программного многоуровневого коммутатора Open vSwitch, связанная с потерей значимости целого числа, позволяющая нарушителю выполнить произвольный код в целевой системе
BDU:2023-00291
Уязвимость программного многоуровневого коммутатора Open vSwitch, связанная с потерей значимости целого числа, позволяющая нарушителю выполнить произвольный код в целевой системе
Modified: 2024-11-21
CVE-2019-25076
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.
- https://arxiv.org/abs/2011.09107
- https://dl.acm.org/citation.cfm?doid=3359989.3365431
- https://sites.google.com/view/tuple-space-explosion
- https://www.youtube.com/watch?v=5cHpzVK0D28
- https://www.youtube.com/watch?v=DSC3m-Bww64
- https://arxiv.org/abs/2011.09107
- https://dl.acm.org/citation.cfm?doid=3359989.3365431
- https://sites.google.com/view/tuple-space-explosion
- https://www.youtube.com/watch?v=5cHpzVK0D28
- https://www.youtube.com/watch?v=DSC3m-Bww64
Modified: 2024-11-21
CVE-2021-3905
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
- https://access.redhat.com/security/cve/CVE-2021-3905
- https://bugzilla.redhat.com/show_bug.cgi?id=2019692
- https://github.com/openvswitch/ovs-issues/issues/226
- https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349
- https://security.gentoo.org/glsa/202311-16
- https://ubuntu.com/security/CVE-2021-3905
- https://access.redhat.com/security/cve/CVE-2021-3905
- https://bugzilla.redhat.com/show_bug.cgi?id=2019692
- https://github.com/openvswitch/ovs-issues/issues/226
- https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349
- https://security.gentoo.org/glsa/202311-16
- https://ubuntu.com/security/CVE-2021-3905
Modified: 2024-11-21
CVE-2022-4337
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
- https://github.com/openvswitch/ovs/pull/405
- https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5319
- https://www.openwall.com/lists/oss-security/2022/12/21/4
- https://github.com/openvswitch/ovs/pull/405
- https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5319
- https://www.openwall.com/lists/oss-security/2022/12/21/4
Modified: 2024-11-21
CVE-2022-4338
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
- https://github.com/openvswitch/ovs/pull/405
- https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5319
- https://www.openwall.com/lists/oss-security/2022/12/21/4
- https://github.com/openvswitch/ovs/pull/405
- https://mail.openvswitch.org/pipermail/ovs-dev/2022-December/400596.html
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5319
- https://www.openwall.com/lists/oss-security/2022/12/21/4
Modified: 2025-04-23
CVE-2023-1668
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
- https://bugzilla.redhat.com/show_bug.cgi?id=2137666
- https://lists.debian.org/debian-lts-announce/2023/05/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2GUNS3WSJG4TUDKZ5L7FXGJMVOD6EJZ/
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5387
- https://www.openwall.com/lists/oss-security/2023/04/06/1
- https://bugzilla.redhat.com/show_bug.cgi?id=2137666
- https://lists.debian.org/debian-lts-announce/2023/05/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2GUNS3WSJG4TUDKZ5L7FXGJMVOD6EJZ/
- https://security.gentoo.org/glsa/202311-16
- https://www.debian.org/security/2023/dsa-5387
- https://www.openwall.com/lists/oss-security/2023/04/06/1