Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5265

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7ovn2.11Fix deferred
Fast Datapath for RHEL 7ovn2.12Fix deferred
Fast Datapath for RHEL 7ovn2.13Fix deferred
Fast Datapath for RHEL 8ovn2.11Fix deferred
Fast Datapath for RHEL 8ovn2.12Fix deferred
Fast Datapath for RHEL 8ovn2.13Fix deferred
Fast Datapath for RHEL 8ovn22.03Fix deferred
Fast Datapath for RHEL 8ovn22.06Fix deferred
Fast Datapath for RHEL 8ovn22.09Fix deferred
Fast Datapath for RHEL 8ovn22.12Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2453458ovn: ovn: Heap Over-Read in ICMP Error Response Generation

EPSS

Процентиль: 48%
0.00629
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
nvd
5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
debian
5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
github
5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 9.8
fstec
5 месяцев назад

Уязвимость программного многоуровневого коммутатора Open vSwitch, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 48%
0.00629
Низкий

6.5 Medium

CVSS3