CVE Feed

    Dashboard / CVE / CVE-2026-5265

    CVE-2026-5265

    When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

    Published:Apr 6, 2026
    Last Modified:Jun 17, 2026
    EPS:Apr 24, 2026
    EPSS Score:0.00629
    CVSS Score:6.5

    Affected Products

    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Fast Datapath

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High