{"id":"AZL-86781","summary":"CVE-2026-34956 affecting package openvswitch for versions less than 3.3.0-3","details":"A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.","modified":"2026-08-28T17:48:00.273993945Z","published":"2026-05-05T16:16:11Z","upstream":["CVE-2026-34956"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34956"}],"affected":[{"package":{"name":"openvswitch","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/openvswitch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86781.json"}}],"schema_version":"1.9.0"}