CVE-2026-5367 Details
Description
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
A vulnerability exists in OVN (Open Virtual Network) versions through 2.13 and 22.03, 22.06, and 22.09. A remote attacker can exploit this flaw by sending specially crafted DHCPv6 SOLICIT packets with an exaggerated Client ID length. This manipulation causes the ovn-controller to perform an out-of-bounds read, accessing sensitive information in heap memory. The leaked data is then sent back to the attacker's virtual machine port. This issue arises when DHCPv6 is enabled for logical switch ports, allowing the exploitation of user-controlled packet data without proper validation.
There is no recommended fix for this vulnerability, as disabling DHCPv6 on affected logical ports will also interrupt legitimate DHCPv6 traffic from connected workloads.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | redhat-SADP |
| CWE-130 | Improper Handling of Length Parameter Inconsistency | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 24, 2026 | CVE Modified | CVE |
| Apr 24, 2026 | New CVE Received | [email protected] |