[Bug 2053113] Re: Insufficient validation of incoming BFD packets.

2024-03-22 Thread James Page
This bug was fixed in the package ovn - 24.03.1-2ubuntu1~cloud0 --- ovn (24.03.1-2ubuntu1~cloud0) jammy-caracal; urgency=medium . * New upstream release for the Ubuntu Cloud Archive. . ovn (24.03.1-2ubuntu1) noble; urgency=medium . * d/rules: Fix check for ovs populated from

[Bug 2053113] Re: Insufficient validation of incoming BFD packets.

2024-03-21 Thread James Page
@cvalean - yep - I've just push these updates into ovn-22.03 proposed; as we work through testing they will get released to the updates pocket as well. ** Also affects: cloud-archive/ovn-22.03 Importance: Undecided Status: New ** Changed in: cloud-archive/ovn-22.03 Status: New =>

[Bug 2053113] Re: Insufficient validation of incoming BFD packets.

2024-03-21 Thread James Page
** Changed in: cloud-archive Status: Invalid => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2053113 Title: Insufficient validation of incoming BFD packets. To manage notifica

[Bug 2053113] Re: Insufficient validation of incoming BFD packets.

2024-03-21 Thread Chris Valean
Hi James, We are using ovn 22.03 on top of focal from this repo [0] which seems to not have been updated to have the fix for the CVE described here. Would it be possible for that to get an update as well? Thank you! [0] http://ubuntu-cloud.archive.canonical.com/ubuntu/dists/focal- updates/ovn-22.

[Bug 2053113] Re: Insufficient validation of incoming BFD packets.

2024-03-14 Thread James Page
I've uploaded both UCA only updates to the staging area for the associated release series. ** Information type changed from Private Security to Public Security ** Changed in: ovn (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ub