<Vulnerability name="CVE-2026-36499">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-04T00:00:00</PublicDate>
    <Bugzilla id="2484881" url="https://bugzilla.redhat.com/show_bug.cgi?id=2484881" xml:lang="en:us">
openvswitch: Open vSwitch: Denial of service via resource exhaustion due to missing upper-bound check
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Open vSwitch. A missing upper-bound check in udpif_set_threads() allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads, causing resource exhaustion and denial of service. Reported against Open vSwitch v3.6.90; affects deployments where OVSDB is writable by untrusted parties.
    </Details>
    <Statement xml:lang="en:us">
Open vSwitch is vulnerable to denial of service via resource exhaustion in udpif_set_threads() due to a missing upper-bound check on thread counts. An attacker with high privileges (OVSDB write access) can configure excessive handler or revalidation threads to exhaust system resources. CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H (4.4). Affects FDP, OpenShift OVS RPMs, RHEL-7 ELS, and Fedora openvswitch packages.
    </Statement>
    <Mitigation xml:lang="en:us">
Restrict OVSDB write access to trusted administrators only. Do not expose OVSDB management interfaces to untrusted networks.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10::fastdatapath">
        <ProductName>Fast Datapath for RHEL 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.5</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10::fastdatapath">
        <ProductName>Fast Datapath for RHEL 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.6</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7::fastdatapath">
        <ProductName>Fast Datapath for RHEL 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7::fastdatapath">
        <ProductName>Fast Datapath for RHEL 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.10</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7::fastdatapath">
        <ProductName>Fast Datapath for RHEL 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.11</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7::fastdatapath">
        <ProductName>Fast Datapath for RHEL 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7::fastdatapath">
        <ProductName>Fast Datapath for RHEL 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.13</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.11</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.13</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.15</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.16</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.17</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8::fastdatapath">
        <ProductName>Fast Datapath for RHEL 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.1</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.17</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.0</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.1</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.3</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.4</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.5</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9::fastdatapath">
        <ProductName>Fast Datapath for RHEL 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.6</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>openvswitch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch2.17</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.0</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>openvswitch3.1</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-36499
https://nvd.nist.gov/vuln/detail/CVE-2026-36499
http://open.com
https://github.com/majdlatah/OVS-Other-Config-Bug
    </References>
</Vulnerability>