CVE-2020-35498 is a denial-of-service vulnerability in Open vSwitch, affecting various distributions including Debian and Fedora. A remote attacker can exploit a limitation in userspace packet parsing by sending a specially crafted packet, leading to an overly wide megaflow in the kernel and causing system unavailability. Rated 7.5 HIGH, this vulnerability has a low attack complexity and requires no user interaction or privileges. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, < 2.5.12CPE matchmatch criteria | cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* | ||
>= 2.6.0, < 2.6.10CPE matchmatch criteria | cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.13CPE matchmatch criteria | cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.11CPE matchmatch criteria | cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.9CPE matchmatch criteria | cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
openvswitch: limitation in the OVS packet parsing in userspace leads to DoS
Feb 10, 2021A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Feb 9, 2021