Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5265

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 6.5

Описание

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7ovn2.11Fix deferred
Fast Datapath for RHEL 7ovn2.12Fix deferred
Fast Datapath for RHEL 7ovn2.13Fix deferred
Fast Datapath for RHEL 8ovn2.11Fix deferred
Fast Datapath for RHEL 8ovn2.12Fix deferred
Fast Datapath for RHEL 8ovn2.13Fix deferred
Fast Datapath for RHEL 8ovn22.03Fix deferred
Fast Datapath for RHEL 8ovn22.06Fix deferred
Fast Datapath for RHEL 8ovn22.09Fix deferred
Fast Datapath for RHEL 8ovn22.12Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2453458ovn: ovn: Heap Over-Read in ICMP Error Response Generation

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
nvd
3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
debian
3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
github
3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

suse-cvrf
около 1 месяца назад

Security update for openvswitch

6.5 Medium

CVSS3