FlawAtlas
Search the atlas
SUSE-SU-2026:0290-1 Not scored

Security update for openvswitch3

This update for openvswitch3 fixes the following issues: Update to v3.1.7: - CVE-2023-3966: openvswitch, openvswitch3: Invalid memory access in Geneve with HW offload (bsc#1219465). - CVE-2024-2182: openvswitch: ov: insufficient validation of incoming BFD packets may lead to denial of service (bsc#1255435). - CVE-2023-1668: openvswitch: remote traffic denial of service via crafted packets with IP proto 0 (bsc#1210054). - CVE-2023-3153: openvswitch,openvswitch3: service monitor MAC flow is not rate limited (bsc#1212125). - CVE-2023-5366: openvswitch: missing masks on a final stage with ports trie (bsc#1216002).

Exploit probability Not scored
Published January 26, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS openvswitch3
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS openvswitch3
SUSE:Linux Enterprise Micro 5.5 openvswitch3
SUSE:Linux Enterprise Server 15 SP5-LTSS openvswitch3
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 openvswitch3
openSUSE:Leap 15.6 openvswitch3

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0290-1

This update for openvswitch3 fixes the following issues: Update to v3.1.7: - CVE-2023-3966: openvswitch, openvswitch3: Invalid memory access in Geneve with HW offload (bsc#1219465). - CVE-2024-2182: openvswitch: ov: insufficient validation of incoming BFD packets may lead to denial of service (bsc#1255435). - CVE-2023-1668: openvswitch: remote traffic denial of service via crafted packets with IP proto 0 (bsc#1210054). - CVE-2023-3153: openvswitch,openvswitch3: service monitor MAC flow is not rate limited (bsc#1212125). - CVE-2023-5366: openvswitch: missing masks on a final stage with ports trie (bsc#1216002).

View original source

05 / REFERENCES

Further evidence