Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-5367 Details

Description

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2026:11694 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:11695 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:11696 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:11698 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:11700 redhat-SADP

see all 25 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-130Improper Handling of Length Parameter Inconsistencyredhat-SADP
CWE-130Improper Handling of Length Parameter Inconsistency[email protected]

Affected Products

No affected product data is available for this CVE.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-5367
NVD Published Date:
Apr 24, 2026
NVD Last Modified:
Aug 25, 2026
Source:
[email protected]
CVE-2026-5367 Details - Not Deferred