https://seclists.org/oss-sec/2026/q1/430: [ADVISORY] CVE-2026-34956: Open vSwitch: Invalid memory access in conntrack FTP alg.
Published Mar 31, 2026
·Updated
Affected Software
1 affected component
Open vSwitch Open vSwitch>=2.8.0<=3.7.0
Frequently Asked Questions
1
What is the severity of CVE-2026-34956?
CVE-2026-34956 is considered a critical vulnerability due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2026-34956?
To mitigate CVE-2026-34956, you should upgrade Open vSwitch to the latest patched version provided by the maintainers.
3
What causes CVE-2026-34956?
CVE-2026-34956 is caused by invalid memory accesses triggered by specially crafted FTP payloads processed by the conntrack implementation.
4
Which versions of Open vSwitch are affected by CVE-2026-34956?
CVE-2026-34956 affects multiple versions of Open vSwitch prior to the release of the security patch.
5
Can CVE-2026-34956 lead to remote code execution?
Yes, CVE-2026-34956 can potentially allow remote code execution due to the exploitation of invalid memory accesses.