216.73.217.22

CVE-2026-5367

· Published 24/04/2026 13:16 · Modified 24/04/2026 14:39

Labels: CVE-2026-5367 2026-04-24CVE-2026-5367CWE-130[email protected]

Essential information

Published
24/04/2026 13:16
Modified
24/04/2026 14:39
Author
Creator
CVSS
8.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CVSS metrics

Description

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
open virtual network / ovn controller cpe:2.3:a:open_virtual_network:ovn_controller:*:*:*:*:*:*:*:*

References