CVE-2026-5265
MEDIUMOvn: ovn: heap over-read in icmp error response generation - security issue
Title source: cnaDescription
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.
References (13)
Core 13
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-5265
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11694
https://access.redhat.com/errata/RHSA-2026:11694
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11695
https://access.redhat.com/errata/RHSA-2026:11695
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11696
https://access.redhat.com/errata/RHSA-2026:11696
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11698
https://access.redhat.com/errata/RHSA-2026:11698
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11700
https://access.redhat.com/errata/RHSA-2026:11700
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11701
https://access.redhat.com/errata/RHSA-2026:11701
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:11702
https://access.redhat.com/errata/RHSA-2026:11702
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:22110
https://access.redhat.com/errata/RHSA-2026:22110
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:22111
https://access.redhat.com/errata/RHSA-2026:22111
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2453458
https://bugzilla.redhat.com/show_bug.cgi?id=2453458
Scores
CVSS v3
6.5
EPSS
0.0063
EPSS Percentile
45.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-130
Status
published
Products (13)
Red Hat/Fast Datapath for Red Hat Enterprise Linux 10
0:25.03.2-100.el10fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 10
0:25.09.2-103.el10fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 8
0:21.12.0-145.el8fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 8
0:23.06.4-30.el8fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9
0:23.06.4-30.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9
0:23.09.6-16.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9
0:24.03.7-82.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9
0:25.03.2-100.el9fdp
Red Hat/Fast Datapath for Red Hat Enterprise Linux 9
0:25.09.2-103.el9fdp
Red Hat/Fast Datapath for RHEL 10
... and 3 more
Published
Apr 24, 2026
Tracked Since
Apr 24, 2026