{"id":"CVE-2021-3905","details":"A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.","modified":"2026-07-08T23:57:46.030515Z","published":"2022-08-23T16:15:10.177Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"21.10"},{"last_affected":"21.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"35"},{"last_affected":"35"}]},{"cpes":["cpe:2.3:a:redhat:enterprise_linux_fast_datapath:7.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:enterprise_linux_fast_datapath:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_fast_datapath"}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2021-3905"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202311-16"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2019692"},{"type":"FIX","url":"https://github.com/openvswitch/ovs-issues/issues/226"},{"type":"FIX","url":"https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349"},{"type":"FIX","url":"https://ubuntu.com/security/CVE-2021-3905"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openvswitch/ovs","events":[{"introduced":"0"},{"fixed":"db7c86e5d03cd9018739e5fa47cc6be0bad246a0"},{"fixed":"803ed12e31b0377c37d7aa8c94b3b92f2081e349"}],"database_specific":{"cpe":"cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.17.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.1.0pre2","v1.1.0pre1","v1.0.1","v1.0.0","v0.99.2","v0.99.1","v0.99.0","v0.90.4","v0.90.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3905.json","vanir_signatures_modified":"2026-07-08T23:57:46Z","vanir_signatures":[{"id":"CVE-2021-3905-2f55292c","signature_type":"Function","signature_version":"v1","source":"https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349","target":{"file":"lib/ipf.c","function":"ipf_extract_frags_from_batch"},"deprecated":false,"digest":{"length":620,"function_hash":"59206550191124162597306143656796702807"}},{"digest":{"line_hashes":["113026978509954193576006793526224427224","336035935748019679433616447587111359138","188532591581163255405121483877259391893","49480125028801656152872840088186111378"],"threshold":0.9},"id":"CVE-2021-3905-bc45e5fb","signature_type":"Line","signature_version":"v1","source":"https://github.com/openvswitch/ovs/commit/803ed12e31b0377c37d7aa8c94b3b92f2081e349","target":{"file":"lib/ipf.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}