ThreatCluster

Multiple CVEs Identified in Open vSwitch Vulnerabilities

First seen 18 Feb 2026, 11:17 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities in Open vSwitch have been reported, CVE-2025-37998 and CVE-2025-21761. CVE-2025-37998, published on May 29, 2025, addresses unsafe attribute parsing in the output_userspace() function, while CVE-2025-21761, published on February 27, 2025, involves the use of RCU protection in the ovs_vport_cmd_fill_info() function. Both vulnerabilities could potentially affect users of Open vSwitch.

Timeline

2025-02-27
CVE-2025-21761 published
2025-05-29
CVE-2025-37998 published
2026-02-18
Information published for CVE-2025-37998
2026-02-18
Information published for CVE-2025-21761