Out-of-Bounds Read Vulnerability in Open Virtual Network
CVE-2026-5367

8.6HIGH

What is CVE-2026-5367?

A flaw in the Open Virtual Network (OVN) allows a remote attacker to exploit specific vulnerabilities by sending specially crafted DHCPv6 SOLICIT packets. By inflating the Client ID length, an attacker could trigger the ovn-controller to read data beyond the allocated boundaries. This out-of-bounds read may inadvertently expose sensitive information residing in heap memory, which can be retrieved by the attacker's virtual machine, leading to potential data breaches.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.