Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-5265

3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-5265

4 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5265

3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-5265

3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-whr7-6788-jg2p

3 месяца назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2481-1

около 1 месяца назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2476-1

около 2 месяцев назад

Security update for openvswitch3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2475-1

около 2 месяцев назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2463-1

около 2 месяцев назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20972-1

около 2 месяцев назад

Security update for openvswitch

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-whr7-6788-jg2p

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2481-1

Security update for openvswitch

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2476-1

Security update for openvswitch3

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2475-1

Security update for openvswitch

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2463-1

Security update for openvswitch

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20972-1

Security update for openvswitch

около 2 месяцев назад

Уязвимостей на страницу