Out-of-bounds read in Open Virtual Network - CVE-2026-5265
Published: April 20, 2026
Open Virtual Network
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the pinctrl ICMP error response handler when generating ICMP Destination Unreachable or Packet Too Big responses from crafted IP packets with inflated length fields. A remote attacker can send a specially crafted packet to disclose sensitive information.
Exploitation requires triggering an ICMP error path, such as reject ACL handling, gateway MTU checks, or a load balancer configured to reject traffic when no backends are available.