CVE-2026-34956
published 2026-05-05CVE-2026-34956: A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.40%
33.1th percentile
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 3.7.1-1 (forky) | openvswitch 3.7.1-1 (forky) |
| openvswitch | openvswitch | — | — |
| rhosp-rhel8 | openstack-neutron-openvswitch-agent | — | — |
| rhosp-rhel9 | openstack-neutron-openvswitch-agent | — | — |
| rhosp13 | openstack-neutron-openvswitch-agent | — | — |
| rhosp13 | openstack-openvswitch-base | — | — |
| rhosp13 | openstack-ovn-base | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q5f5-xxh8-jx9h: A flaw was found in Open vSwitch
ghsa_unreviewed·2026-05-05
CVE-2026-34956 [MEDIUM] CWE-120 GHSA-q5f5-xxh8-jx9h: A flaw was found in Open vSwitch
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Red Hat
openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
vendor_redhat·2026-03-31·CVSS 5.9
CVE-2026-34956 [MEDIUM] CWE-120 openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Statement: This vulnerability in Open vSwitch, leading to a heap access error and potential denial of service, is not exploitable in default Red Hat configurations. Exploitation requires Open vSwitch to be specifically configured with FTP helpers over the userspace datapath, which is not enabled by default.
Mitigation: Optionally, avoid using alg=ftp flows. These are n
Debian
CVE-2026-34956: openvswitch
vendor_debian·2026
CVE-2026-34956 CVE-2026-34956: openvswitch
bookworm: open
bullseye: open
forky: resolved (fixed in 3.7.1-1)
sid: resolved (fixed in 3.7.1-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34956 openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
bugzilla·2026-03-31·CVSS 5.9
CVE-2026-34956 [MEDIUM] CVE-2026-34956 openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
CVE-2026-34956 openvswitch: Open vSwitch: Denial of Service via malformed FTP EPASV command
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Wiz
CVE-2026-34956 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-34956 [MEDIUM] CVE-2026-34956 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34956 :
Linux Debian vulnerability analysis and mitigation
heap overflow with a specially crafted FTP packet
Source : NVD
Published April 2, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Echo
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
openvswitch
Sources
NVD
Debian 11, 12, 13 No Fix Added at: Apr 02, 2026
Debian 14 Has Fix Added at: Apr 02, 2026
Echo No Fix Added at: Apr 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Debian vulnerabilities:
CVE ID
Severity
Score
2026-05-05
Published