A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade ovn25.03-vtep-debuginfoUpgrade ovn25.03-vtepUpgrade ovn25.03-host-debuginfoUpgrade ovn25.03-hostUpgrade ovn25.03-debuginfoUpgrade ovn25.03-central-debuginfoUpgrade ovn25.09-host-debuginfoUpgrade ovn25.09-debuginfoUpgrade ovn25.03Upgrade ovn25.09Upgrade ovn25.09-centralUpgrade ovn25.09-vtep-debuginfoUpgrade ovn25.03-centralUpgrade ovn25.09-hostUpgrade ovn25.09-vtepUpgrade ovn25.09-central-debuginfoUpgrade ovn25.03-debugsourceUpgrade ovn25.09-debugsource | Jun 3, 2026 | Apr 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub