CVE-2020-35498

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/02/2021
Last modified:
23/04/2025

Description

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.12 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.10 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.13 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.11 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.9 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.10.0 (including) 2.10.7 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.11.0 (including) 2.11.6 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.12.0 (including) 2.12.3 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.13.0 (including) 2.13.3 (excluding)
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* 2.14.0 (including) 2.14.2 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*