CVE-2026-34956

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Configurations

No configuration.

History

05 May 2026, 17:17

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/31/15 -

05 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 16:16

Updated : 2026-05-05 19:31


NVD link : CVE-2026-34956

Mitre link : CVE-2026-34956

CVE.ORG link : CVE-2026-34956


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')