CVE-2026-36499EPSS p14.8%
CVE-2026-36499CVE-2026-36499
Description
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.24% probability of exploitation · percentile 14.8% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-06 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.