CVE-2020-35498: Debian Linux
High severity, CVSS 7.5. EPSS: 8% chance of exploitation in the next 30 days.
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 33 only
- Openvswitch Openvswitch: from 2.5.0, before 2.5.12 (fixed in 2.5.12); from 2.6.0, before 2.6.10 (fixed in 2.6.10); from 2.7.0, before 2.7.13 (fixed in 2.7.13); from 2.8.0, before 2.8.11 (fixed in 2.8.11); from 2.9.0, before 2.9.9 (fixed in 2.9.9); from 2.10.0, before 2.10.7 (fixed in 2.10.7); …
Published 2021-02-11. Last modified 2026-06-17.