Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.41% | — | OpenvswitchAI | 4/6/2026 | 22/7/2026 | A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion. | |
| Pendiente de análisis | Media (5.9) | 0.64% | — | Openvswitch Open VswitchAI | 5/5/2026 | 1/9/2026 | A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service… | |
| Pendiente de análisis | Media (6.5) | 0.66% | — | Openvswitch OVNAI | 24/4/2026 | 17/6/2026 | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a… | |
| Aplazada | Alta (8.1) | 0.86% | — | Openvswitch OVNAI | 23/1/2025 | 17/6/2026 | A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual… | |
| Analizada | Alta (7.5) | 1.0% | — | OpenvswitchFedoraproject Fedora | 22/2/2024 | 17/6/2026 | A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled. | |
| Modificada | Alta (7.5) | 0.57% | — | Openvswitch | 19/1/2024 | 17/6/2026 | openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c. | |
| Modificada | Media (5.5) | 0.39% | — | OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+1 | 6/10/2023 | 17/6/2026 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. | |
| Modificada | Crítica (9.8) | 1.3% | — | OpenvswitchDebian Linux | 10/1/2023 | 17/6/2026 | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. | |
| Modificada | Crítica (9.8) | 1.3% | — | OpenvswitchDebian Linux | 10/1/2023 | 17/6/2026 | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. | |
| Modificada | Media (5.8) | 2.3% | — | Openvswitch | 8/9/2022 | 17/6/2026 | The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space… | |
| Modificada | Media (6.5) | 0.30% | — | Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform | 29/8/2022 | 17/6/2026 | A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts… | |
| Modificada | Alta (7.5) | 2.0% | — | OpenvswitchRedhat Enterprise Linux Fast DatapathCanonical Ubuntu LinuxFedoraproject Fedora | 23/8/2022 | 17/6/2026 | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments. | |
| Modificada | Media (5.5) | 1.2% | — | Openvswitch | 20/7/2021 | 17/6/2026 | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action. | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.5) | 8.0% | — | OpenvswitchDebian LinuxFedoraproject Fedora | 11/2/2021 | 17/6/2026 | A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to… | |
| Modificada | Media (4.9) | 2.0% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu LinuxDebian Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding. | |
| Modificada | Alta (7.5) | 2.5% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to… | |
| Modificada | Media (4.3) | 1.9% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu LinuxDebian Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier,… | |
| Modificada | Media (5.9) | 1.2% | — | Openvswitch | 2/10/2017 | 17/6/2026 | In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful… | |
| Modificada | Crítica (9.8) | 2.8% | — | Openvswitch | 29/5/2017 | 17/6/2026 | In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`. | |
| Modificada | Crítica (9.8) | 2.4% | — | Openvswitch | 29/5/2017 | 17/6/2026 | In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely. | |
| Modificada | Media (6.5) | 1.0% | — | Openvswitch | 29/5/2017 | 17/6/2026 | In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch. | |
| Modificada | Alta (8.8) | 0.94% | — | Openvswitch | 29/5/2017 | 17/6/2026 | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch. | |
| Modificada | Crítica (9.8) | 2.9% | — | OpenvswitchDebian LinuxRedhat OpenstackRedhat Virtualization+1 | 23/5/2017 | 17/6/2026 | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`. | |
| Modificada | Crítica (9.8) | 6.4% | — | OpenvswitchRedhat Openshift | 3/7/2016 | 17/6/2026 | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command. |