CVE-2026-25804Disclosure(linuxfoundation / antrea)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • antrea

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
antrea

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-06: 2Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25804 Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has… https://www.cve.org/CVERecord?id=CVE-2026-25804

    Post summary

    The snippet announces CVE‑2026‑25804 affecting Antrea before certain releases, offering minimal technical context and no evidence of exploitation or mitigation.

    00010188
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25804: Antrea Integer Overflow: When 65536 Equals 0 (and Admin Rules Don't Matter) A critical integer overflow vulnerability in Antrea's priority assignment logic allows low-priority network policies to wrap around and supersede high-priority... https://cvereports.com/reports/CVE-2026-25804

    Post summary

    The post announces CVE‑2026‑25804, detailing an integer overflow in Antrea’s priority logic that permits low‑priority policies to override higher ones.

    0000045
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationantrea-kubernetes-

Explore more