Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34956

Опубликовано: 31 мар. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.

Отчет

This vulnerability in Open vSwitch, leading to a heap access error and potential denial of service, is not exploitable in default Red Hat configurations. Exploitation requires Open vSwitch to be specifically configured with FTP helpers over the userspace datapath, which is not enabled by default.

Меры по смягчению последствий

Optionally, avoid using alg=ftp flows. These are not usually configured.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchFix deferred
Fast Datapath for RHEL 7openvswitch2.10Fix deferred
Fast Datapath for RHEL 7openvswitch2.11Fix deferred
Fast Datapath for RHEL 7openvswitch2.12Fix deferred
Fast Datapath for RHEL 7openvswitch2.13Fix deferred
Fast Datapath for RHEL 7openvswitch-selinux-extra-policyFix deferred
Fast Datapath for RHEL 7ovn2.11Fix deferred
Fast Datapath for RHEL 7ovn2.12Fix deferred
Fast Datapath for RHEL 8openvswitch2.11Fix deferred
Fast Datapath for RHEL 8openvswitch2.12Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2453459openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command

EPSS

Процентиль: 33%
0.00405
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.

CVSS3: 5.9
nvd
3 месяца назад

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.

CVSS3: 5.9
msrc
3 месяца назад

Openvswitch: open vswitch: denial of service via malformed ftp epasv command

CVSS3: 5.9
debian
3 месяца назад

A flaw was found in Open vSwitch. When Open vSwitch is configured with ...

suse-cvrf
4 месяца назад

Security update for openvswitch

EPSS

Процентиль: 33%
0.00405
Низкий

5.9 Medium

CVSS3