CVE-2026-5265Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-20); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-25: 104-2004-2104-2304-25
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-211
General1
2026-04-231
Patch1
2026-04-251
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OVN (Open Virtual Network) CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation https://www.openwall.com/lists/oss-security/2026/04/20/4 CVE-2026-5367: Heap over-read in DHCPv6 Client ID processing https://www.openwall.com/lists/oss-security/2026/04/20/5

    Post summary

    The post announces two heap over‑read vulnerabilities in Open Virtual Network (CVE‑2026‑5265 and CVE‑2026‑5367) with concise technical descriptions, but no exploits, patches, or active exploitation reports.

    02092613
    4.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تنبيه أمان OVN: ثغرات خطيرة في القراءة الزائدة من الذاكرة Heap تعرض البيانات الحساسة للتسرب أصدر فريق الشبكة الافتراضية المفتوحة (OVN) تحذيرًا أمنيًا بشأن ثغرتين خطيرتين في القراءة الزائدة من الذاكرة Heap، وهما CVE-2026-5265 و CVE-2026-5367. يمكن أن تؤدي هذه الثغرات إلى تسرب البيانات الحساسة. يوصى بتحديث الأنظمة المتضررة وتفعيل إجراءات الأمان اللازمة. — يُنصح بتحديث البرامج ومراجعة الإعدادات الأمنية. 🔗 للمزيد: https://securityonline.info/ovn-heap-over-read-packet-leakage-advisory/

    Post summary

    The advisory announces critical heap over‑read vulnerabilities (CVE-2026-5265/5367) and urges users to apply patches and review security settings.

    00030900
    268 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5265 When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP he… https://www.cve.org/CVERecord?id=CVE-2026-5265

    Post summary

    The text describes the technical details of CVE-2026-5265, highlighting improper copying of packet data during ICMP error response generation.

    0000087
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5265 Re https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5265

    Post summary

    The message simply references CVE-2026-5265 and links to a Vulmon page for further details, offering no additional information on exploitation, patches, or technical specifics.

    0000023
    4.0K followersView on X

Explore more