Unknown · Openvswitch · CVE-2026-36499
**Name of the Vulnerable Software and Affected Versions**
Open vSwitch version 3.6.90
**Description**
A missing upper-bound check in the `udpif set threads()` function allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can lead to a denial of service (DoS) through resource exhaustion, which occurs when a system lacks the necessary memory or CPU cycles to function properly.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.