There's nothing I can do about this bug, I don't think it is useful to
keep it open forever.
1. No upstream fix exists. Zero commits, issues, or PRs in
openvswitch/ovs referencing the TSE attack ("tuple space explosion",
"flow expansion", or the CVE id). The paper (Ghali et al., ACM CCS '19)
was disclosed to the OVS security process in 2019, and upstream never
merged a patch — the master classifier and docs have no mitigation
whatsoever.
2. It's a design-level DoS, not a patchable bug: crafted flow patterns
explode the megaflow classifier's Tuple Space Search subtables, delaying
legitimate traffic. Any "fix" is architectural (limiting megaflow
caching = permanent performance trade-off), which upstream declined to do.
3. Debian's security tracker agrees: every suite is vulnerable/unfixed,
buster/bullseye <no-dsa> "Minor issue", bookworm/trixie <postponed> —
"Minor issue, revisit when fixed upstream". Nothing moved in 7 years
across any distro (Red Hat, SUSE, Ubuntu same).
What we've done in production, is that we're just monitoring of there's
too many of these to-be-classified packets, to react to a DoS. OVS is
just vulnerable to traffic attack, just like so many components, and
that's the only way to "fix" this.
Cheers,
Thomas Goirand (zigo)