Описание
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| openvswitch | fixed | 3.7.1-1 | package | |
| openvswitch | no-dsa | trixie | package | |
| openvswitch | no-dsa | bookworm | package |
Примечания
https://www.openwall.com/lists/oss-security/2026/03/31/15
Introduced by: https://github.com/openvswitch/ovs/commit/bd5e81a0e596dd012d11824cce69b7c80ae107c5 (v2.9.0)
Fixed by: https://github.com/openvswitch/ovs/commit/8e81545d9d1461758c72fbd08ce1f52e472bca94 (v3.3.9)
Fixed by: https://github.com/openvswitch/ovs/commit/ba03a85296709b3939c8e232afe59c4cb8140936 (v3.4.6)
Fixed by: https://github.com/openvswitch/ovs/commit/354afecf9f0a2eaec4f8dcc8464b9124519c66de (v3.5.4)
Fixed by: https://github.com/openvswitch/ovs/commit/1291c22c8ba59d40843502e97b37537bc53dfc53 (v3.6.3)
Fixed by: https://github.com/openvswitch/ovs/commit/a9785c7e1df73fc3dd5f9ca3816a884e63f2f9e0 (v3.7.1)
https://mail.openvswitch.org/pipermail/ovs-dev/2026-March/431425.html
Связанные уязвимости
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Openvswitch: open vswitch: denial of service via malformed ftp epasv command