SB20260824104 - Incorrect Calculation of Buffer Size in Linux kernel openvswitch
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-74664)
CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of reply buffer sizing in ovs_flow_cmd_new() in net/openvswitch/datapath.c when processing flow update requests with mismatched identifiers. A local user can send a specially crafted flow update request to cause a denial of service.
The issue can occur when a request using a UFID falls back to flow key lookup and the matched flow requires a larger echoed reply identifier than the preallocated reply buffer provides.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00f987f066e802793a37dd2167459e67cf2cf2ec
- https://git.kernel.org/stable/c/20751193d83be2e9735d4faee71375691c09cd13
- https://git.kernel.org/stable/c/23716dd9d8d46a5908536b73dc085e62f2b5c237
- https://git.kernel.org/stable/c/5d1c224dd914579524a183a514c12b95095d12ce
- https://git.kernel.org/stable/c/696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc
- https://git.kernel.org/stable/c/69f40ccf85074981340847d650a9cbf9adabfbbe
- https://git.kernel.org/stable/c/87d0c0040b5d4b61de51ae39132c4c46709f2f77
- https://git.kernel.org/stable/c/bd8ca84d48cd9a4f6fc63df26512c55e1d339927