PT-2026-33836 · Ovn · Ovn

Published

2026-04-20

·

Updated

2026-06-01

·

CVE-2026-5367

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OVN (affected versions not specified)
Description A flaw in OVN (Open Virtual Network) allows a remote attacker to cause the ovn-controller to perform an out-of-bounds read by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length. This heap over-read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port via DHCPv6 and ICMP responses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-5367
RHSA-2026:11694
RHSA-2026:11695
RHSA-2026:11696
RHSA-2026:11698
RHSA-2026:11700
RHSA-2026:11701
RHSA-2026:11702

Affected Products

Ovn