openvswitch (2.5.5-0ubuntu0.16.04.2) xenial-security; urgency=medium
* SECURITY UPDATE: assertion failure when decoding a group mod
- debian/patches/CVE-2018-17204.patch: don't assert-fail decoding bad
OF1.5 group mod type or command in lib/ofp-util.c.
- CVE-2018-17204
* SECURITY UPDATE: buffer overread during BUNDLE action decoding
- debian/patches/CVE-2018-17206.patch: avoid overread in
lib/ofp-actions.c.
- CVE-2018-17206
-- Marc Deslauriers <email address hidden> Thu, 04 Oct 2018 11:45:07 -0400