cbcvebase.
CVE-2021-3905
published 2022-08-23

CVE-2021-3905: A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.58%
72.7th percentile
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianopenvswitch
fedoraprojectfedora
msrccm1_openvswitch_2.15.1-2_on_cbl_mariner_1.0
openvswitchopenvswitch< 2.17.02.17.0
openvswitchopenvswitch>= 0 < 2.9.8-0ubuntu0.18.04.22.9.8-0ubuntu0.18.04.2
openvswitchopenvswitch>= 0 < 2.13.3-0ubuntu0.20.04.22.13.3-0ubuntu0.20.04.2
openvswitchopenvswitch>= 0 < 2.17.0~git20220105.0d1ffb7-0ubuntu12.17.0~git20220105.0d1ffb7-0ubuntu1
redhatenterprise_linux_fast_datapath
redhatenterprise_linux_fast_datapath

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.