logo

OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks

ID: d9223488-61df-5eab-8d1f-93a026b60ead

STIX ID: report--d9223488-61df-5eab-8d1f-93a026b60ead

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

The OVN team disclosed two critical heap over-read vulnerabilities (CVE-2026-5265 and CVE-2026-5367) where crafted ICMP or DHCPv6 packets can cause ovn-controller to read and return adjacent heap memory in replies, enabling information disclosure from virtualized environments; patches are available for OVN 24.03+ and workarounds exist but may disrupt legitimate traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.