Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

github логотип

GHSA-whr7-6788-jg2p

5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-5265

5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-5265

6 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5265

5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-5265

5 месяцев назад

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-12869

5 месяцев назад

Уязвимость программного многоуровневого коммутатора Open vSwitch, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2481-1

3 месяца назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2476-1

3 месяца назад

Security update for openvswitch3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2475-1

3 месяца назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2463-1

3 месяца назад

Security update for openvswitch

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20972-1

3 месяца назад

Security update for openvswitch

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-whr7-6788-jg2p

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big resp ...

CVSS3: 6.5
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-12869

Уязвимость программного многоуровневого коммутатора Open vSwitch, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.8
1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2481-1

Security update for openvswitch

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2476-1

Security update for openvswitch3

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2475-1

Security update for openvswitch

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2463-1

Security update for openvswitch

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20972-1

Security update for openvswitch

3 месяца назад

Уязвимостей на страницу