Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-12871

Опубликовано: 16 апр. 2026
Источник: fstec
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Уязвимость программного многоуровневого коммутатора Open vSwitch связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Сообщество свободного программного обеспечения
ООО «РусБИТех-Астра»
Red Hat, Inc.

Наименование ПО

Debian GNU/Linux
Astra Linux Special Edition
Red Hat OpenShift Container Platform
Open vSwitch

Версия ПО

12 (Debian GNU/Linux)
1.7 (Astra Linux Special Edition)
4 (Red Hat OpenShift Container Platform)
4.7 (Astra Linux Special Edition)
13 (Debian GNU/Linux)
до 26.03.1 (Open vSwitch)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7
Сообщество свободного программного обеспечения Debian GNU/Linux 13

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,5)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,8)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для Open vSwitch:
https://github.com/ovn-org/ovn/commit/78f6ce612403d6343f1e3782cbfff691d411dee4
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-5367
https://deb.freexian.com/extended-lts/tracker/CVE-2026-5367
Для ОС Astra Linux:
обновить пакет ovn до 23.03.1-1~deb12u2.astra2 или более высокой версии: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0820SE17
Для программных продуктов Red Hat, Inc.:
https://access.redhat.com/security/cve/CVE-2026-5367
Для ОС Astra Linux:
обновить пакет ovn до 23.03.1-1~deb12u2.astra2 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0907SE47

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 57%
0.00868
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.6
ubuntu
5 месяцев назад

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

CVSS3: 8.6
redhat
5 месяцев назад

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

CVSS3: 8.6
nvd
5 месяцев назад

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

CVSS3: 8.6
debian
5 месяцев назад

A flaw was found in OVN (Open Virtual Network). A remote attacker, by ...

CVSS3: 8.6
github
5 месяцев назад

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

EPSS

Процентиль: 57%
0.00868
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2