In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: reallocate update replies for mismatched IDs
ovs_flow_cmd_new() preallocates the optional reply skb before it takes ovs_mutex and before it knows which existing flow will be updated.
That is normally fine because the skb is sized from the request flow identifier. That identifier also becomes the inserted flow's identifier. For updates, however, a request with a UFID may miss the UFID lookup and then fall back to the flow key lookup. That lookup can legitimately find an existing key-identified flow. UFIDs are optional and the flow key is the primary identifier.
For echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's identifier, not the request identifier used for the preallocation. A short request UFID can therefore leave too little room for the key identifier. The fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the update path.
Once the update target has been resolved, reallocate the reply skb if the matched flow needs a larger reply than the request identifier allowed. Do this before replacing the actions so the request can still fail cleanly if the rare extra allocation fails.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bpftool6.18Upgrade kernel6.18-modules-extra-commonUpgrade perf6.18Upgrade python3-perf6.18Upgrade kernel6.18-tools-debuginfoUpgrade kernel6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-headersUpgrade kernel6.18-toolsUpgrade python3-perf6.18-debuginfoUpgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18-debuginfoUpgrade kernel6.18-develUpgrade perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-modules-extraUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-tools-develUpgrade microvm-kernel6.18 | Sep 30, 2026 | Aug 22, 2026 |
| Debian | — | Upgrade linux-6.12Upgrade linux | Aug 26, 2026 | Aug 26, 2026 |
| Redhat_linux | — | No solution exists | Aug 25, 2026 | Aug 22, 2026 |
| Ubuntu | — | Upgrade linux-image-5.15.0-1123-azure-fipsUpgrade linux-image-5.15.0-1117-aws-fipsUpgrade linux-image-lowlatency-64kUpgrade linux-image-kvmUpgrade linux-image-gcp-fipsUpgrade linux-image-intel-iot-realtime-5.15Upgrade linux-image-generic-64k-hwe-20.04Upgrade linux-image-lowlatency-64k-hwe-20.04Upgrade linux-image-5.15.0-1109-intel-iot-realtimeUpgrade linux-image-generic-lpaeUpgrade linux-image-5.15.0-1100-gkeopUpgrade linux-image-lowlatencyUpgrade linux-image-gke-5.15Upgrade linux-image-fips-5.15Upgrade linux-image-azure-lts-22.04Upgrade linux-image-aws-lts-22.04Upgrade linux-image-5.15.0-1113-gkeUpgrade linux-image-azure-fipsUpgrade linux-image-azure-fdeUpgrade linux-image-5.15.0-198-generic-64kUpgrade linux-image-generic-64kUpgrade linux-image-aws-64k-5.15Upgrade linux-image-gcpUpgrade linux-image-azureUpgrade linux-image-aws-64k-lts-22.04Upgrade linux-image-virtualUpgrade linux-image-5.15.0-195-lowlatency-64kUpgrade linux-image-oem-20.04dUpgrade linux-image-lowlatency-hwe-20.04Upgrade linux-image-5.15.0-1112-intel-iotgUpgrade linux-image-oracle-5.15Upgrade linux-image-oem-20.04bUpgrade linux-image-gcp-lts-22.04Upgrade linux-image-ibmUpgrade linux-image-5.15.0-1114-oracleUpgrade linux-image-generic-hwe-20.04Upgrade linux-image-ibm-5.15Upgrade linux-image-genericUpgrade linux-image-fipsUpgrade linux-image-xilinx-zynqmp-5.15Upgrade linux-image-virtual-hwe-20.04Upgrade linux-image-azure-fips-5.15Upgrade linux-image-oem-20.04Upgrade linux-image-intel-iot-realtimeUpgrade linux-image-5.15.0-1117-aws-64kUpgrade linux-image-5.15.0-1109-kvmUpgrade linux-image-generic-lpae-5.15Upgrade linux-image-5.15.0-198-generic-lpaeUpgrade linux-image-aws-fips-5.15Upgrade linux-image-5.15.0-198-genericUpgrade linux-image-gkeUpgrade linux-image-5.15.0-1122-azure-fdeUpgrade linux-image-lowlatency-64k-5.15Upgrade linux-image-azure-fde-5.15Upgrade linux-image-5.15.0-1118-gcpUpgrade linux-image-5.15.0-1117-awsUpgrade linux-image-oem-20.04cUpgrade linux-image-lowlatency-5.15Upgrade linux-image-intel-iotg-5.15Upgrade linux-image-intelUpgrade linux-image-virtual-5.15Upgrade linux-image-realtime-5.15Upgrade linux-image-kvm-5.15Upgrade linux-image-generic-lpae-hwe-20.04Upgrade linux-image-generic-5.15Upgrade linux-image-gcp-fips-5.15Upgrade linux-image-gcp-5.15Upgrade linux-image-azure-cvmUpgrade linux-image-5.15.0-195-lowlatencyUpgrade linux-image-5.15.0-1080-xilinx-zynqmpUpgrade linux-image-generic-64k-5.15Upgrade linux-image-5.15.0-198-fipsUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-realtimeUpgrade linux-image-oracle-lts-22.04Upgrade linux-image-oracleUpgrade linux-image-awsUpgrade linux-image-5.15.0-1118-gcp-fipsUpgrade linux-image-5.15.0-1116-realtimeUpgrade linux-image-5.15.0-1111-ibmUpgrade linux-image-gkeopUpgrade linux-image-aws-5.15Upgrade linux-image-intel-iotgUpgrade linux-image-gkeop-5.15Upgrade linux-image-azure-5.15Upgrade linux-image-aws-fipsUpgrade linux-image-5.15.0-1123-azure | Oct 6, 2026 | Oct 6, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub