CVE-2020-35498: Debian Linux

High severity, CVSS 7.5. EPSS: 8% chance of exploitation in the next 30 days.

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 33 only
  • Openvswitch Openvswitch: from 2.5.0, before 2.5.12 (fixed in 2.5.12); from 2.6.0, before 2.6.10 (fixed in 2.6.10); from 2.7.0, before 2.7.13 (fixed in 2.7.13); from 2.8.0, before 2.8.11 (fixed in 2.8.11); from 2.9.0, before 2.9.9 (fixed in 2.9.9); from 2.10.0, before 2.10.7 (fixed in 2.10.7); …

Published 2021-02-11. Last modified 2026-06-17.