CVE-2020-35498 PUBLISHED

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

EPSS 5.76% · 90.4th percentile

Risk Scores

EPSS Score
5.76%
90.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenvswitch0, 2.4.0-0ubuntu5, 2.5.0~git20160129.46a88d9-0ubuntu1
Ubuntu:20.04:LTSopenvswitch*, 2.12.1~git20191107.7accd1302-0ubuntu1, 2.12.90~git20200107.af683565b-0ubuntu1
Ubuntu:18.04:LTSopenvswitch2.8.0-0ubuntu2, 2.8.1-0ubuntu2, 2.8.1-0ubuntu3

Timeline

References

Open in Interactive Console →