- Issued:
- 2024-01-24
- Updated:
- 2024-01-24
RHBA-2024:0392 - Bug Fix Advisory
Synopsis
ovn23.09 bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for ovn23.09 is now available in Fast Datapath for Red Hat Enterprise Linux 9.
Description
OVN, the Open Virtual Network, is a system to support virtual network abstraction. OVN complements the existing capabilities of OVS to add native support for virtual network abstractions, such as virtual L2 and L3 overlays and security groups.
Bug Fix(es) and Enhancement(s):
- OVN does not check length of OpenFlow FLOW_MOD messages (BZ#1955167)
- [ovn] Traffic flooding to the fabric when using VLAN backed networks (BZ#2087779)
- [RFE] Add information at NB DB about where gateway chassis port are bound (BZ#2107515)
- Use the libc native backtrace mechanism exposed in OvS (BZ#2164058)
- Add FDB aging mechanism. FutureFeature (BZ#2179942)
- Add MAC binding timestamp refresh mechanism (BZ#2212315)
- ovn-controller replace CT zone UUID names with LR/LS names (BZ#2224199)
- LB skip_snat improperly applied with affinity_timeout (BZ#2224260)
- packet replied for load balance is not snated if both lb and nat are added (BZ#2224399)
- [OVN SCALE] ovn-controller: Inefficient condition updates for Port_Binding table (BZ#2224400)
- Use stable hashing when routing packets over ECMP. (BZ#2224402)
- [RFE] Extend DHCPv6 with FQDN option (BZ#2224403)
- Investigate failure WARN in "load-balancer template IPv4/IPv6" system tests (BZ#2226631)
- Add incremental processing in ovn-northd for port groups. (BZ#2228162)
- Support binding remote ports in ovn-northd (BZ#2231218)
- [OVN] qos on tunnel interface doesn't work(ovn-nbctl set Logical_Switch_Port $portname options:qos_max_rate) (BZ#2234349)
- ovn-controller: Incremental processing may grow conjunctive flows in size indefinitely (BZ#2239060)
- UEFI (edk2/ovmf) network boot with OVN fail because no DHCP release reply (BZ#2239061)
- Revisit OVN's logic of flushing conntrack for LR (BZ#2245944)
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux Fast Datapath 9 x86_64
- Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE) 9 ppc64le
- Red Hat Enterprise Linux Fast Datapath (for IBM z Systems) 9 s390x
- Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64) 9 aarch64
Fixes
- BZ - 1955167 - OVN does not check length of OpenFlow FLOW_MOD messages
- BZ - 2087779 - [ovn] Traffic flooding to the fabric when using VLAN backed networks
- BZ - 2107515 - [RFE] Add information at NB DB about where gateway chassis port are bound
- BZ - 2164058 - Use the libc native backtrace mechanism exposed in OvS
- BZ - 2179942 - Add FDB aging mechanism.
- BZ - 2212315 - Add MAC binding timestamp refresh mechanism
- BZ - 2224199 - ovn-controller replace CT zone UUID names with LR/LS names
- BZ - 2224260 - LB skip_snat improperly applied with affinity_timeout
- BZ - 2224399 - packet replied for load balance is not snated if both lb and nat are added
- BZ - 2224400 - [OVN SCALE] ovn-controller: Inefficient condition updates for Port_Binding table
- BZ - 2224402 - Use stable hashing when routing packets over ECMP.
- BZ - 2224403 - [RFE] Extend DHCPv6 with FQDN option
- BZ - 2226631 - Investigate failure WARN in "load-balancer template IPv4/IPv6" system tests
- BZ - 2228162 - Add incremental processing in ovn-northd for port groups.
- BZ - 2231218 - Support binding remote ports in ovn-northd
- BZ - 2234349 - [OVN] qos on tunnel interface doesn't work(ovn-nbctl set Logical_Switch_Port $portname options:qos_max_rate)
- BZ - 2239060 - ovn-controller: Incremental processing may grow conjunctive flows in size indefinitely
- BZ - 2239061 - UEFI (edk2/ovmf) network boot with OVN fail because no DHCP release reply
- BZ - 2245944 - Revisit OVN's logic of flushing conntrack for LR
CVEs
(none)
References
(none)
Red Hat Enterprise Linux Fast Datapath 9
| SRPM | |
|---|---|
| ovn23.09-23.09.0-73.el9fdp.src.rpm | SHA-256: 36ae7c5c3bc34ba234630ced18bb77f2af3933129a31c25f3ace965dcb3c4eb9 |
| x86_64 | |
| ovn23.09-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: fb3018cdd56b06497d82100ee7861269ed4a196f8f04c8c2bf6561140b6de356 |
| ovn23.09-central-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: d295b40169ad3fec78ae36ec6a10794dc559fbd5a229636a0fe2fa906821e830 |
| ovn23.09-central-debuginfo-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: 0f749db53b2a5340121aad21905f7e2088829f4e4d6768aa6021997d1a4752ec |
| ovn23.09-debuginfo-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: 3eea306c554ff1e78b4e8d024c9b7273ba665a8e59b090bca7f74b360b0d50ae |
| ovn23.09-debugsource-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: 43ae2c4e9605164be97a0bbab857bc362fb6564fcb952ffc19d86416dc73bf77 |
| ovn23.09-host-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: da1250513c7c89aa924848ea5fa087cdb7a92a1e0924c0d95f2222ff2c512c8d |
| ovn23.09-host-debuginfo-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: e7ba7a296df01cbc066259b1ea17b5cd725b39213fdba4fac786ec1a8950489a |
| ovn23.09-vtep-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: 219a15ac244ee84ea50026c940489d453b9b26dd438b1f02fec837f3bd829ada |
| ovn23.09-vtep-debuginfo-23.09.0-73.el9fdp.x86_64.rpm | SHA-256: f40425ffe2cf889ae356446ed81dd4c4f4357b2335976ff1dab53b0e7366c83c |
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE) 9
| SRPM | |
|---|---|
| ovn23.09-23.09.0-73.el9fdp.src.rpm | SHA-256: 36ae7c5c3bc34ba234630ced18bb77f2af3933129a31c25f3ace965dcb3c4eb9 |
| ppc64le | |
| ovn23.09-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: 0262735197f0f40c94e1563b230703f51db736ff319ab18a4e5cf381396a023d |
| ovn23.09-central-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: 9afb53bc55b9f64ba59f97ab65a2ee02f111010cf668913fe201e1a12557d9b7 |
| ovn23.09-central-debuginfo-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: e21bb37dc953bbc6adad7479b99273c979515798cf5e2e12da43a8c695288433 |
| ovn23.09-debuginfo-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: fe3f5ce10602c29d7199a29c9a87ec309ca9f89b09dbdac5c0339d9acf66e4f3 |
| ovn23.09-debugsource-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: 3864b75da34ef2aa582d956425857edbcb1150253e2d29580419a09b50f428c7 |
| ovn23.09-host-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: 319ba909c85e02303042a6e22891f03cdb709b6bbef135319b00079f28163473 |
| ovn23.09-host-debuginfo-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: ee2306d972f447e3fcd9ae18c9d313cccf1ed7a2e1411ea1a456b8c767254cc6 |
| ovn23.09-vtep-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: 1a39c33581cd23f587f71d98020d80c66e5f4bbdb51d718728103373e3c2556a |
| ovn23.09-vtep-debuginfo-23.09.0-73.el9fdp.ppc64le.rpm | SHA-256: fbca94f089d2e3e5ef6b0152109835b16878d3b0c506df1ec19302a0d4f7a16d |
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems) 9
| SRPM | |
|---|---|
| ovn23.09-23.09.0-73.el9fdp.src.rpm | SHA-256: 36ae7c5c3bc34ba234630ced18bb77f2af3933129a31c25f3ace965dcb3c4eb9 |
| s390x | |
| ovn23.09-23.09.0-73.el9fdp.s390x.rpm | SHA-256: a92ff76f1bcee91a034dd91ce9404ef32d1c9329c980068f84375c1cc5ee4cf0 |
| ovn23.09-central-23.09.0-73.el9fdp.s390x.rpm | SHA-256: ddd203d6a99118b100013eb1f232334c63ebe69a36436dd9a42c119d8d87cd73 |
| ovn23.09-central-debuginfo-23.09.0-73.el9fdp.s390x.rpm | SHA-256: 8e3cd9d4cf68b4c2cfc4b9ec1a30a3f1431028c9ef3651fb93c906ee1ff7f9a4 |
| ovn23.09-debuginfo-23.09.0-73.el9fdp.s390x.rpm | SHA-256: 6268722535a9d8b0bf2d349cb0dcfbff820b38af64d032277295fd61189fa176 |
| ovn23.09-debugsource-23.09.0-73.el9fdp.s390x.rpm | SHA-256: 302f4f3c22664b3520c9219f86f7a48913f894cc4246eadb7d99a82822c603b3 |
| ovn23.09-host-23.09.0-73.el9fdp.s390x.rpm | SHA-256: 27a02e58c4bd92771d427f3b1d191d9b30333a190524778e88b196d01fce85d3 |
| ovn23.09-host-debuginfo-23.09.0-73.el9fdp.s390x.rpm | SHA-256: d7c345f033d0850d55e02fe2aebb382d232c045607d3f35e850eaca8d2e0cb36 |
| ovn23.09-vtep-23.09.0-73.el9fdp.s390x.rpm | SHA-256: cc8601c1bbc7aca0043ef4f8ca67d0fbac319258c903d4c232cd3dcc6937ead9 |
| ovn23.09-vtep-debuginfo-23.09.0-73.el9fdp.s390x.rpm | SHA-256: 5d82fed90464693559bfb634a1c1fad43f1a66c1c6e095452fa516838b5dbd29 |
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64) 9
| SRPM | |
|---|---|
| ovn23.09-23.09.0-73.el9fdp.src.rpm | SHA-256: 36ae7c5c3bc34ba234630ced18bb77f2af3933129a31c25f3ace965dcb3c4eb9 |
| aarch64 | |
| ovn23.09-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: 54029ac9ef19f05103ed0399dd381d77e60a01a91641b3588e3d33744f8a4d8e |
| ovn23.09-central-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: bf3717c44d2b2dc49f81579cae314f09548cb4102f6974d04b33bf2a801f9ac3 |
| ovn23.09-central-debuginfo-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: 868c3bac16e9059a8bb9455d3386eaae815e518949e1c80525b4cf37c99eac0c |
| ovn23.09-debuginfo-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: d6bd114501e016d07e5b3214dc87fc02c3372fb5811b460f768f39ca1024e0aa |
| ovn23.09-debugsource-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: d2b33a0092a6ac6036845c971c45a90d5b1b5ab134ad2356a947cb864a8cb71a |
| ovn23.09-host-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: cddc24d7337a8f10746cc938195d4825f77799e944c878effaca16291a8494a5 |
| ovn23.09-host-debuginfo-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: 22041073ce362c8a1e809bc99ab52b27c2f2d10be27db1d235f28c5b0ade18fd |
| ovn23.09-vtep-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: 2b3a4c47060db3648897c3d6884fd716e60af5943733cf9a52df3794b0565c85 |
| ovn23.09-vtep-debuginfo-23.09.0-73.el9fdp.aarch64.rpm | SHA-256: 90688bbd94005ca0fe8a8c2373d78af079faca5c63f7d4b0383cd10f8d8670b2 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.