Bug 2455863 (CVE-2026-5367)

Summary: CVE-2026-5367 ovn: OVN: Information disclosure via crafted DHCPv6 packets
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: echaudro, fleitner, ktraynor, rkhan, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-04-13   

Description OSIDB Bzimport 2026-04-07 08:12:27 UTC
Multiple versions of OVN (Open Virtual Network) are vulnerable to
crafted DHCPv6 packets that could potentially read out-of-bounds,
leaking adjacent info stored on the heap.

OVN supports configuring DHCPv6 options for Logical Switch Ports.
When configured we allow handling of DHCPv6 requests in a userspace
thread called pinctrl. The thread accesses user-controlled packet data
and copies some of it in the process of creating a reply packet.


When building a DHCPv6 ADVERTISE reply, the handler echoes the
Client ID option using the option's self-declared length without
validating it against the actual packet bounds. A workload can send
a crafted DHCPv6 SOLICIT with an inflated Client ID length field,
causing ovn-controller to copy heap memory beyond the valid packet
data into the reply. The reply is then delivered back to the
attacker's VM port.

Comment 2 errata-xmlrpc 2026-04-29 12:41:31 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 8

Via RHSA-2026:11694 https://access.redhat.com/errata/RHSA-2026:11694

Comment 3 errata-xmlrpc 2026-04-29 12:41:42 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 8

Via RHSA-2026:11695 https://access.redhat.com/errata/RHSA-2026:11695

Comment 4 errata-xmlrpc 2026-04-29 12:41:49 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11696 https://access.redhat.com/errata/RHSA-2026:11696

Comment 5 errata-xmlrpc 2026-04-29 12:41:52 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11698 https://access.redhat.com/errata/RHSA-2026:11698

Comment 6 errata-xmlrpc 2026-04-29 12:42:50 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11701 https://access.redhat.com/errata/RHSA-2026:11701

Comment 7 errata-xmlrpc 2026-04-29 12:46:24 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11702 https://access.redhat.com/errata/RHSA-2026:11702

Comment 8 errata-xmlrpc 2026-04-29 12:46:46 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11700 https://access.redhat.com/errata/RHSA-2026:11700

Comment 9 errata-xmlrpc 2026-06-01 00:11:13 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 10

Via RHSA-2026:22111 https://access.redhat.com/errata/RHSA-2026:22111

Comment 10 errata-xmlrpc 2026-06-01 00:11:27 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 10

Via RHSA-2026:22110 https://access.redhat.com/errata/RHSA-2026:22110