CVE-2026-5265

MEDIUM

Ovn: ovn: heap over-read in icmp error response generation - security issue

Title source: cna
STIX 2.1

Description

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

References (13)

Core 13
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-5265
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11694
https://access.redhat.com/errata/RHSA-2026:11694
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11695
https://access.redhat.com/errata/RHSA-2026:11695
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11696
https://access.redhat.com/errata/RHSA-2026:11696
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11698
https://access.redhat.com/errata/RHSA-2026:11698
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11700
https://access.redhat.com/errata/RHSA-2026:11700
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11701
https://access.redhat.com/errata/RHSA-2026:11701
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:11702
https://access.redhat.com/errata/RHSA-2026:11702
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:22110
https://access.redhat.com/errata/RHSA-2026:22110
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:22111
https://access.redhat.com/errata/RHSA-2026:22111
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2453458
https://bugzilla.redhat.com/show_bug.cgi?id=2453458

Scores

CVSS v3 6.5
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-130
Status published
Products (13)
Red Hat/Fast Datapath for Red Hat Enterprise Linux 10 0:25.03.2-100.el10fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 10 0:25.09.2-103.el10fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 8 0:21.12.0-145.el8fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 8 0:23.06.4-30.el8fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9 0:23.06.4-30.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9 0:23.09.6-16.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9 0:24.03.7-82.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9 0:25.03.2-100.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9 0:25.09.2-103.el9fdp
Red Hat/Fast Datapath for RHEL 10
... and 3 more
Published Apr 24, 2026
Tracked Since Apr 24, 2026