OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks
ID: d9223488-61df-5eab-8d1f-93a026b60ead
STIX ID: report--d9223488-61df-5eab-8d1f-93a026b60ead
Feed Name: securityonline.info
Threat Score
The OVN team disclosed two critical heap over-read vulnerabilities (CVE-2026-5265 and CVE-2026-5367) where crafted ICMP or DHCPv6 packets can cause ovn-controller to read and return adjacent heap memory in replies, enabling information disclosure from virtualized environments; patches are available for OVN 24.03+ and workarounds exist but may disrupt legitimate traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
