Bug 2455863 (CVE-2026-5367) - CVE-2026-5367 ovn: OVN: Information disclosure via crafted DHCPv6 packets
Summary: CVE-2026-5367 ovn: OVN: Information disclosure via crafted DHCPv6 packets
Keywords:
Status: NEW
Alias: CVE-2026-5367
Deadline: 2026-04-13
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-07 08:12 UTC by OSIDB Bzimport
Modified: 2026-06-01 00:11 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:11694 0 None None None 2026-04-29 12:41:32 UTC
Red Hat Product Errata RHSA-2026:11695 0 None None None 2026-04-29 12:41:44 UTC
Red Hat Product Errata RHSA-2026:11696 0 None None None 2026-04-29 12:41:50 UTC
Red Hat Product Errata RHSA-2026:11698 0 None None None 2026-04-29 12:41:53 UTC
Red Hat Product Errata RHSA-2026:11700 0 None None None 2026-04-29 12:46:47 UTC
Red Hat Product Errata RHSA-2026:11701 0 None None None 2026-04-29 12:42:52 UTC
Red Hat Product Errata RHSA-2026:11702 0 None None None 2026-04-29 12:46:26 UTC
Red Hat Product Errata RHSA-2026:22110 0 None None None 2026-06-01 00:11:29 UTC
Red Hat Product Errata RHSA-2026:22111 0 None None None 2026-06-01 00:11:14 UTC

Description OSIDB Bzimport 2026-04-07 08:12:27 UTC
Multiple versions of OVN (Open Virtual Network) are vulnerable to
crafted DHCPv6 packets that could potentially read out-of-bounds,
leaking adjacent info stored on the heap.

OVN supports configuring DHCPv6 options for Logical Switch Ports.
When configured we allow handling of DHCPv6 requests in a userspace
thread called pinctrl. The thread accesses user-controlled packet data
and copies some of it in the process of creating a reply packet.


When building a DHCPv6 ADVERTISE reply, the handler echoes the
Client ID option using the option's self-declared length without
validating it against the actual packet bounds. A workload can send
a crafted DHCPv6 SOLICIT with an inflated Client ID length field,
causing ovn-controller to copy heap memory beyond the valid packet
data into the reply. The reply is then delivered back to the
attacker's VM port.

Comment 2 errata-xmlrpc 2026-04-29 12:41:31 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 8

Via RHSA-2026:11694 https://access.redhat.com/errata/RHSA-2026:11694

Comment 3 errata-xmlrpc 2026-04-29 12:41:42 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 8

Via RHSA-2026:11695 https://access.redhat.com/errata/RHSA-2026:11695

Comment 4 errata-xmlrpc 2026-04-29 12:41:49 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11696 https://access.redhat.com/errata/RHSA-2026:11696

Comment 5 errata-xmlrpc 2026-04-29 12:41:52 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11698 https://access.redhat.com/errata/RHSA-2026:11698

Comment 6 errata-xmlrpc 2026-04-29 12:42:50 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11701 https://access.redhat.com/errata/RHSA-2026:11701

Comment 7 errata-xmlrpc 2026-04-29 12:46:24 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11702 https://access.redhat.com/errata/RHSA-2026:11702

Comment 8 errata-xmlrpc 2026-04-29 12:46:46 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:11700 https://access.redhat.com/errata/RHSA-2026:11700

Comment 9 errata-xmlrpc 2026-06-01 00:11:13 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 10

Via RHSA-2026:22111 https://access.redhat.com/errata/RHSA-2026:22111

Comment 10 errata-xmlrpc 2026-06-01 00:11:27 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 10

Via RHSA-2026:22110 https://access.redhat.com/errata/RHSA-2026:22110


Note You need to log in before you can comment on or make changes to this bug.