CVE-2021-36980
published 2021-07-20CVE-2021-36980: Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.18%
64.3th percentile
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 2.15.0+ds1-10 (bookworm) | openvswitch 2.15.0+ds1-10 (bookworm) |
| msrc | cbl2_openvswitch_2.17.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_openvswitch_2.15.1-1_on_cbl_mariner_1.0 | — | — |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-2+deb11u1 | 2.15.0+ds1-2+deb11u1 |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-10 | 2.15.0+ds1-10 |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-10 | 2.15.0+ds1-10 |
| openvswitch | openvswitch | >= 0 < 2.15.0+ds1-10 | 2.15.0+ds1-10 |
| openvswitch | openvswitch | 2.11.0 – 2.15.0 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open vSwitch vulnerability
vendor_ubuntu·2021-09-08
CVE-2021-36980 Open vSwitch vulnerability
Title: Open vSwitch vulnerability
Summary: Open vSwitch could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that Open vSwitch incorrectly handled decoding RAW_ENCAP
actions. A remote attacker could use this issue to cause Open vSwitch to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
vendor_msrc·2021-07-13·CVSS 5.5
CVE-2021-36980 [MEDIUM] CWE-416 Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to ref
Red Hat
openvswitch: use-after-free in decode_NXAST_RAW_ENCAP during the decoding of a RAW_ENCAP action
vendor_redhat·2021-02-23·CVSS 5.5
CVE-2021-36980 [MEDIUM] CWE-416 openvswitch: use-after-free in decode_NXAST_RAW_ENCAP during the decoding of a RAW_ENCAP action
openvswitch: use-after-free in decode_NXAST_RAW_ENCAP during the decoding of a RAW_ENCAP action
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
Open vSwitch (aka openvswitch) has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.
Package: openvswitch (Fast Datapath for RHEL 7) - Will not fix
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Not affected
Package: ope
Debian
CVE-2021-36980: openvswitch - Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in dec...
vendor_debian·2021·CVSS 5.5
CVE-2021-36980 [MEDIUM] CVE-2021-36980: openvswitch - Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in dec...
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
Scope: local
bookworm: resolved (fixed in 2.15.0+ds1-10)
bullseye: resolved (fixed in 2.15.0+ds1-2+deb11u1)
forky: resolved (fixed in 2.15.0+ds1-10)
sid: resolved (fixed in 2.15.0+ds1-10)
trixie: resolved (fixed in 2.15.0+ds1-10)
GHSA
GHSA-ww48-mfpv-wc3r: Open vSwitch (aka openvswitch) 2
ghsa_unreviewed·2022-05-24
CVE-2021-36980 [MEDIUM] CWE-416 GHSA-ww48-mfpv-wc3r: Open vSwitch (aka openvswitch) 2
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
OSV
CVE-2021-36980: Open vSwitch (aka openvswitch) 2
osv·2021-07-20·CVSS 5.5
CVE-2021-36980 [MEDIUM] CVE-2021-36980: Open vSwitch (aka openvswitch) 2
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openvswitch/OSV-2020-2197.yamlhttps://github.com/openvswitch/ovs/commit/38744b1bcb022c611712527f039722115300f58fhttps://github.com/openvswitch/ovs/commit/65c61b0c23a0d474696d7b1cea522a5016a8aeb3https://github.com/openvswitch/ovs/commit/6d67310f4d2524b466b98f05ebccc1add1e8cf35https://github.com/openvswitch/ovs/commit/77cccc74deede443e8b9102299efc869a52b65b2https://github.com/openvswitch/ovs/commit/8ce8dc34b5f73b30ce0c1869af9947013c3c6575https://github.com/openvswitch/ovs/commit/9926637a80d0d243dbf9c49761046895e9d1a8e2https://security.gentoo.org/glsa/202311-16https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openvswitch/OSV-2020-2197.yamlhttps://github.com/openvswitch/ovs/commit/38744b1bcb022c611712527f039722115300f58fhttps://github.com/openvswitch/ovs/commit/65c61b0c23a0d474696d7b1cea522a5016a8aeb3https://github.com/openvswitch/ovs/commit/6d67310f4d2524b466b98f05ebccc1add1e8cf35https://github.com/openvswitch/ovs/commit/77cccc74deede443e8b9102299efc869a52b65b2https://github.com/openvswitch/ovs/commit/8ce8dc34b5f73b30ce0c1869af9947013c3c6575https://github.com/openvswitch/ovs/commit/9926637a80d0d243dbf9c49761046895e9d1a8e2https://security.gentoo.org/glsa/202311-16
2021-07-20
Published