Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
CVE-2021-36980
Score 5.5 from GitHub Security Advisory published 2022-05-24. NVD baseline CVSS 5.5; sources differ by 0.0.
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 5.5
- EG Score
- 5.5(medium)
- EG Risk
- 25(Track)EG Risk 25/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity55% × 45%Exploitation1% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 1%
- EPSS %ILE
- 66%
- KEV
- Not listed
Published
July 20, 2021
Last Modified
May 5, 2025
References (18)
- cve@mitrehttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851
- cve@mitrehttps://github.com/google/oss-fuzz-vulns/blob/main/vulns/openvswitch/OSV-2020-2197.yaml
- cve@mitrehttps://github.com/openvswitch/ovs/commit/38744b1bcb022c611712527f039722115300f58f
- cve@mitrehttps://github.com/openvswitch/ovs/commit/65c61b0c23a0d474696d7b1cea522a5016a8aeb3
- cve@mitrehttps://github.com/openvswitch/ovs/commit/6d67310f4d2524b466b98f05ebccc1add1e8cf35
- cve@mitrehttps://github.com/openvswitch/ovs/commit/77cccc74deede443e8b9102299efc869a52b65b2
- cve@mitrehttps://github.com/openvswitch/ovs/commit/8ce8dc34b5f73b30ce0c1869af9947013c3c6575
- cve@mitrehttps://github.com/openvswitch/ovs/commit/9926637a80d0d243dbf9c49761046895e9d1a8e2
- cve@mitrehttps://security.gentoo.org/glsa/202311-16
- af854a3a-2127-422b-91ae-364da2661108https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851
- af854a3a-2127-422b-91ae-364da2661108https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openvswitch/OSV-2020-2197.yaml
- af854a3a-2127-422b-91ae-364da2661108https://github.com/openvswitch/ovs/commit/38744b1bcb022c611712527f039722115300f58f
- af854a3a-2127-422b-91ae-364da2661108https://github.com/openvswitch/ovs/commit/65c61b0c23a0d474696d7b1cea522a5016a8aeb3
- af854a3a-2127-422b-91ae-364da2661108https://github.com/openvswitch/ovs/commit/6d67310f4d2524b466b98f05ebccc1add1e8cf35
- af854a3a-2127-422b-91ae-364da2661108https://github.com/openvswitch/ovs/commit/77cccc74deede443e8b9102299efc869a52b65b2
Patch Availability(7)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | openvswitch-test (2.13.3-0ubuntu0.20.04.2) @ focal | 2026-05-26 | ubuntu |
| redhat | openvswitch2.13-0:2.13.0-102.el7fdp | 2022-11-21 | redhat |
| redhat | openvswitch2.11-0:2.11.3-89.el7fdp | 2021-10-20 | redhat |
| redhat | openvswitch2.15-0:2.15.0-28.el8fdp | 2021-10-18 | redhat |
| redhat | openvswitch2.13-0:2.13.0-114.el8fdp | 2021-06-21 | redhat |
| redhat | openvswitch2.15-0:2.15.0-24.el8fdp | 2021-06-21 | redhat |
| redhat | openvswitch2.11-0:2.11.3-86.el8fdp | 2021-04-12 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(4 across 4 ecosystems)
Debian:11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| openvswitch | 2.15.0+ds1-2 | 2.15.0+ds1-2+deb11u1 | — |
Debian:12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| openvswitch | — | 2.15.0+ds1-10 | — |
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| openvswitch | — | 2.15.0+ds1-10 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| openvswitch | — | 2.15.0+ds1-10 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(9)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
- Microsoft MSRCCVE-2021-369802021-07-29
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
- Red HatRHBA-2021:1163MODERATE2021-02-23
RHBA-2021:1163 — Moderate
- Red HatRHBA-2021:1166MODERATE2021-02-23
RHBA-2021:1166 — Moderate
- Red HatRHBA-2021:2508MODERATE2021-02-23
RHBA-2021:2508 — Moderate
- Red HatRHBA-2021:2509MODERATE2021-02-23
RHBA-2021:2509 — Moderate
- Red HatRHBA-2022:8558MODERATE2021-02-23
RHBA-2022:8558 — Moderate
- Red HatRHSA-2021:3758MODERATE2021-02-23
RHSA-2021:3758 — Moderate
- Red HatRHSA-2021:3942MODERATE2021-02-23
RHSA-2021:3942 — Moderate
- UbuntuUSN-5065-1MEDIUM
Open vSwitch vulnerability
Data Freshness Timeline
(refreshed 8× in last 7d / 34× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 170 total refreshes for this CVE.
- 2026-09-24 14:00 UTCEPSS rescore
- 2026-09-23 13:44 UTCEPSS rescore
- 2026-09-22 14:44 UTCEPSS rescore
- 2026-09-21 20:28 UTCEPSS rescore
- 2026-09-21 20:28 UTCEPSS rescore
- 2026-09-20 20:12 UTCEPSS rescore
- 2026-09-19 15:38 UTCEPSS rescore
- 2026-09-18 19:23 UTCEPSS rescore
- 2026-09-17 19:23 UTCEPSS rescore
- 2026-09-17 19:23 UTCEPSS rescore
- 2026-09-16 14:05 UTCEPSS rescore
- 2026-09-16 14:05 UTCEPSS rescore
- 2026-09-15 03:06 UTCEPSS rescore
- 2026-09-13 16:43 UTCEPSS rescore
- 2026-09-12 14:57 UTCEPSS rescore
- 2026-09-11 14:49 UTCEPSS rescore
- 2026-09-11 09:33 UTCEPSS rescore
- 2026-09-08 21:56 UTCEPSS rescore
- 2026-09-07 15:58 UTCEPSS rescore
- 2026-09-06 13:45 UTCEPSS rescore
- 2026-09-06 13:45 UTCEPSS rescore
- 2026-09-06 12:30 UTCOSV refresh
- 2026-09-05 15:25 UTCEPSS rescore
- 2026-09-04 13:57 UTCEPSS rescore
- 2026-09-04 05:03 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-09-02 14:08 UTCEPSS rescore
- 2026-09-01 13:50 UTCEPSS rescore
- 2026-09-01 03:32 UTCEPSS rescore
- 2026-08-30 19:14 UTCEPSS rescore
- 2026-08-30 01:19 UTCEPSS rescore
- 2026-08-30 01:19 UTCEPSS rescore
- 2026-08-28 21:37 UTCEPSS rescore
- 2026-08-27 14:22 UTCEPSS rescore
- 2026-08-26 14:42 UTCEPSS rescore
- 2026-08-25 13:46 UTCEPSS rescore
- 2026-08-24 14:13 UTCEPSS rescore
- 2026-08-23 00:16 UTCEPSS rescore
- 2026-08-21 23:46 UTCEPSS rescore
- 2026-08-20 22:52 UTCEPSS rescore
- 2026-08-19 23:15 UTCOSV refresh
- 2026-08-19 17:01 UTCEPSS rescore
- 2026-08-18 13:45 UTCEPSS rescore
- 2026-08-17 13:44 UTCEPSS rescore
- 2026-08-16 14:53 UTCEPSS rescore
- 2026-08-16 02:11 UTCEPSS rescore
- 2026-08-16 02:11 UTCEPSS rescore
- 2026-08-15 01:27 UTCEPSS rescore
- 2026-08-13 21:57 UTCEPSS rescore
- 2026-08-12 13:48 UTCEPSS rescore
- 2026-08-11 13:38 UTCEPSS rescore
- 2026-08-09 13:44 UTCEPSS rescore
- 2026-08-08 16:33 UTCEPSS rescore
- 2026-08-07 16:24 UTCEPSS rescore
- 2026-08-06 13:43 UTCEPSS rescore
- 2026-08-05 19:14 UTCEPSS rescore
- 2026-08-04 17:57 UTCOSV refresh
- 2026-08-04 15:06 UTCEPSS rescore
- 2026-08-04 10:34 UTCEPSS rescore
- 2026-08-03 10:33 UTCEPSS rescore
- 2026-08-02 02:24 UTCEPSS rescore
- 2026-08-02 02:24 UTCEPSS rescore
- 2026-08-01 04:13 UTCEPSS rescore
- 2026-07-30 16:25 UTCEPSS rescore
- 2026-07-30 01:28 UTCEPSS rescore
- 2026-07-28 15:33 UTCEPSS rescore
- 2026-07-26 14:52 UTCEPSS rescore
- 2026-07-26 14:52 UTCEPSS rescore
- 2026-07-25 14:15 UTCEPSS rescore
- 2026-07-24 14:15 UTCEPSS rescore
- 2026-07-23 14:16 UTCEPSS rescore
- 2026-07-23 14:16 UTCEPSS rescore
- 2026-07-23 02:03 UTCEG score recompute
- 2026-07-22 22:49 UTCEG score recompute
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-20 17:05 UTCEPSS rescore
- 2026-07-19 14:29 UTCEPSS rescore
- 2026-07-19 14:29 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-18 15:59 UTCOSV refresh
- 2026-07-18 10:02 UTCEPSS rescore
- 2026-07-18 10:02 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-11 08:25 UTCEPSS rescore
- 2026-07-11 08:25 UTCEPSS rescore
- 2026-07-09 19:07 UTCEPSS rescore
- 2026-07-08 15:12 UTCEPSS rescore
- 2026-07-07 13:43 UTCEPSS rescore
- 2026-07-06 16:25 UTCEPSS rescore
- 2026-07-06 02:21 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
Related CVEs(same product + same vendor + same CWE)
Same product
10 shownDebian:11:openvswitch
Same vendor
4 shownredhat:RHSA-2021:3758
Frequently asked(5)
What is CVE-2021-36980?
When was CVE-2021-36980 disclosed?
Is CVE-2021-36980 actively exploited?
What is the CVSS score of CVE-2021-36980?
How do I remediate CVE-2021-36980?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2021-36980
Is Your Infrastructure Affected by CVE-2021-36980?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.