Out-of-bounds read in Open Virtual Network - CVE-2026-5367
Published: April 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the DHCPv6 Client ID option handling in the pinctrl thread when processing crafted DHCPv6 SOLICIT packets. A remote attacker can send a specially crafted DHCPv6 packet with an inflated Client ID length field to disclose sensitive information.
The copied heap memory is included in the DHCPv6 ADVERTISE reply and delivered back to the attacker's VM port. Only logical switch ports configured with DHCPv6 options are exposed.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
SUSE Package Hub 15
Server Applications Module
openSUSE Leap
Red Hat Enterprise Linux Fast Datapath
openvswitch-doc
openvswitch-devel
openvswitch-test
openvswitch-debuginfo
libopenvswitch-2_14-0-debuginfo
openvswitch-debugsource
libopenvswitch-2_14-0
openvswitch
openvswitch-test-debuginfo
openvswitch-pki
python3-ovs
openvswitch-ipsec
openvswitch-vtep
openvswitch-vtep-debuginfo
openvswitch3-pki
openvswitch3-vtep
openvswitch3
openvswitch3-test-debuginfo
python3-ovs3
libopenvswitch-3_1-0
openvswitch3-debuginfo
openvswitch3-devel
openvswitch3-debugsource
openvswitch3-test
openvswitch3-ipsec
openvswitch3-vtep-debuginfo
openvswitch3-doc
libopenvswitch-3_1-0-debuginfo
libopenvswitch-3_5-0
python3-openvswitch-debuginfo
python3-openvswitch
libopenvswitch-3_5-0-debuginfo
ovn-doc
ovn-host-debuginfo
ovn-devel
ovn-central
ovn-docker
ovn-vtep
ovn
ovn-vtep-debuginfo
libovn-20_06-0
ovn-central-debuginfo
ovn-host
libovn-20_06-0-debuginfo
ovn-debuginfo
ovn-2021 (Red Hat package)
ovn3-devel
ovn3
ovn3-central-debuginfo
ovn3-host
libovn-23_03-0-debuginfo
ovn3-docker
ovn3-central
ovn3-vtep-debuginfo
ovn3-doc
ovn3-vtep
ovn3-host-debuginfo
libovn-23_03-0
ovn3-debuginfo
ovn23.06 (Red Hat package)
ovn23.09 (Red Hat package)
ovn24.03 (Red Hat package)
ovn25.03 (Red Hat package)
libovn-25_03-0-debuginfo
libovn-25_03-0
ovn25.09 (Red Hat package)
How to mitigate CVE-2026-5367
openvswitch-doc - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1
openvswitch-devel - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-test - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-debuginfo - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
libopenvswitch-2_14-0-debuginfo - update to 2.14.2-150400.24.35.1
openvswitch-debugsource - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
libopenvswitch-2_14-0 - update to 2.14.2-150400.24.35.1
openvswitch - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-test-debuginfo - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-pki - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
python3-ovs - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1
openvswitch-ipsec - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-vtep - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch-vtep-debuginfo - addressed in versions 2.14.2-150400.24.35.1, 3.1.7-150600.33.15.1, 3.5.4-150700.41.18.1
openvswitch3-pki - update to 3.1.7-150500.3.31.1
openvswitch3-vtep - update to 3.1.7-150500.3.31.1
openvswitch3 - update to 3.1.7-150500.3.31.1
openvswitch3-test-debuginfo - update to 3.1.7-150500.3.31.1
python3-ovs3 - update to 3.1.7-150500.3.31.1
libopenvswitch-3_1-0 - addressed in versions 3.1.7-150500.3.31.1, 3.1.7-150600.33.15.1
openvswitch3-debuginfo - update to 3.1.7-150500.3.31.1
openvswitch3-devel - update to 3.1.7-150500.3.31.1
openvswitch3-debugsource - update to 3.1.7-150500.3.31.1
openvswitch3-test - update to 3.1.7-150500.3.31.1
openvswitch3-ipsec - update to 3.1.7-150500.3.31.1
openvswitch3-vtep-debuginfo - update to 3.1.7-150500.3.31.1
openvswitch3-doc - update to 3.1.7-150500.3.31.1
libopenvswitch-3_1-0-debuginfo - addressed in versions 3.1.7-150500.3.31.1, 3.1.7-150600.33.15.1
libopenvswitch-3_5-0 - update to 3.5.4-150700.41.18.1
python3-openvswitch-debuginfo - update to 3.5.4-150700.41.18.1
python3-openvswitch - update to 3.5.4-150700.41.18.1
libopenvswitch-3_5-0-debuginfo - update to 3.5.4-150700.41.18.1
ovn-doc - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1
ovn-host-debuginfo - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-devel - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-central - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-docker - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-vtep - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-vtep-debuginfo - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
libovn-20_06-0 - update to 20.06.2-150400.24.35.1
ovn-central-debuginfo - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-host - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
libovn-20_06-0-debuginfo - update to 20.06.2-150400.24.35.1
ovn-debuginfo - addressed in versions 20.06.2-150400.24.35.1, 23.03.3-150600.33.15.1, 25.03.3-150700.41.18.1
ovn-2021 (Red Hat package) - update to 21.12.0-145.el8fdp
ovn3-devel - update to 23.03.3-150500.3.31.1
ovn3 - update to 23.03.3-150500.3.31.1
ovn3-central-debuginfo - update to 23.03.3-150500.3.31.1
ovn3-host - update to 23.03.3-150500.3.31.1
libovn-23_03-0-debuginfo - addressed in versions 23.03.3-150500.3.31.1, 23.03.3-150600.33.15.1
ovn3-docker - update to 23.03.3-150500.3.31.1
ovn3-central - update to 23.03.3-150500.3.31.1
ovn3-vtep-debuginfo - update to 23.03.3-150500.3.31.1
ovn3-doc - update to 23.03.3-150500.3.31.1
ovn3-vtep - update to 23.03.3-150500.3.31.1
ovn3-host-debuginfo - update to 23.03.3-150500.3.31.1
libovn-23_03-0 - addressed in versions 23.03.3-150500.3.31.1, 23.03.3-150600.33.15.1
ovn3-debuginfo - update to 23.03.3-150500.3.31.1
ovn23.06 (Red Hat package) - addressed in versions 23.06.4-30.el8fdp, 23.06.4-30.el9fdp
ovn23.09 (Red Hat package) - update to 23.09.6-16.el9fdp
ovn24.03 (Red Hat package) - update to 24.03.7-82.el9fdp
ovn25.03 (Red Hat package) - addressed in versions 25.03.2-100.el9fdp, 25.03.2-100.el10fdp
libovn-25_03-0-debuginfo - update to 25.03.3-150700.41.18.1
libovn-25_03-0 - update to 25.03.3-150700.41.18.1
ovn25.09 (Red Hat package) - addressed in versions 25.09.2-103.el9fdp, 25.09.2-103.el10fdp
External References
Related Security Bulletins
- Two vulnerabilities in Open Virtual Network
- Fast Datapath for Red Hat Enterprise Linux 8 update for ovn-2021
- Fast Datapath for Red Hat Enterprise Linux 8 update for ovn23.06
- Fast Datapath for Red Hat Enterprise Linux 9 update for ovn23.06
- Fast Datapath for Red Hat Enterprise Linux 9 update for ovn23.09
- Fast Datapath for Red Hat Enterprise Linux 9 update for ovn24.03
- Fast Datapath for Red Hat Enterprise Linux 9 update for ovn25.03
- Fast Datapath for Red Hat Enterprise Linux 9 update for ovn25.09
- Fast Datapath for Red Hat Enterprise Linux 10 update for ovn25.03
- Fast Datapath for Red Hat Enterprise Linux 10 update for ovn25.09
- SUSE update for openvswitch
- SUSE update for openvswitch
- SUSE update for openvswitch3
- SUSE update for openvswitch