When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade ovn25.03-central-debuginfoUpgrade ovn25.09-debuginfoUpgrade ovn25.09-vtepUpgrade ovn25.09-vtep-debuginfoUpgrade ovn25.03-centralUpgrade ovn25.09-centralUpgrade ovn25.09-central-debuginfoUpgrade ovn25.03-host-debuginfoUpgrade ovn25.09-hostUpgrade ovn25.03-debugsourceUpgrade ovn25.09-host-debuginfoUpgrade ovn25.03-debuginfoUpgrade ovn25.03-vtep-debuginfoUpgrade ovn25.09-debugsourceUpgrade ovn25.03-hostUpgrade ovn25.03Upgrade ovn25.09Upgrade ovn25.03-vtep | Jun 3, 2026 | Apr 6, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub