Multiple versions of OVN (Open Virtual Network) are vulnerable to crafted DHCPv6 packets that could potentially read out-of-bounds, leaking adjacent info stored on the heap. OVN supports configuring DHCPv6 options for Logical Switch Ports. When configured we allow handling of DHCPv6 requests in a userspace thread called pinctrl. The thread accesses user-controlled packet data and copies some of it in the process of creating a reply packet. When building a DHCPv6 ADVERTISE reply, the handler echoes the Client ID option using the option's self-declared length without validating it against the actual packet bounds. A workload can send a crafted DHCPv6 SOLICIT with an inflated Client ID length field, causing ovn-controller to copy heap memory beyond the valid packet data into the reply. The reply is then delivered back to the attacker's VM port.
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 8 Via RHSA-2026:11694 https://access.redhat.com/errata/RHSA-2026:11694
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 8 Via RHSA-2026:11695 https://access.redhat.com/errata/RHSA-2026:11695
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:11696 https://access.redhat.com/errata/RHSA-2026:11696
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:11698 https://access.redhat.com/errata/RHSA-2026:11698
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:11701 https://access.redhat.com/errata/RHSA-2026:11701
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:11702 https://access.redhat.com/errata/RHSA-2026:11702
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:11700 https://access.redhat.com/errata/RHSA-2026:11700
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 10 Via RHSA-2026:22111 https://access.redhat.com/errata/RHSA-2026:22111
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 10 Via RHSA-2026:22110 https://access.redhat.com/errata/RHSA-2026:22110