CVE-2026-5367Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-20); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-20: 2Mentions · 2026-04-21: 1Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-23: 104-2004-2104-2304-25
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-202
Disclosure2
2026-04-211
General1
2026-04-231
Disclosure1
2026-04-251
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OVN (Open Virtual Network) CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation https://www.openwall.com/lists/oss-security/2026/04/20/4 CVE-2026-5367: Heap over-read in DHCPv6 Client ID processing https://www.openwall.com/lists/oss-security/2026/04/20/5

    Post summary

    The post announces two new OVN heap‑over‑read vulnerabilities (CVE‑2026‑5265 and CVE‑2026‑5367) with brief technical descriptions and links to OpenWall mailing‑list discussions for detail.

    02092613
    4.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 تنبيه أمان OVN: ثغرات خطيرة في القراءة الزائدة من الذاكرة Heap تعرض البيانات الحساسة للتسرب أصدر فريق الشبكة الافتراضية المفتوحة (OVN) تحذيرًا أمنيًا بشأن ثغرتين خطيرتين في القراءة الزائدة من الذاكرة Heap، وهما CVE-2026-5265 و CVE-2026-5367. يمكن أن تؤدي هذه الثغرات إلى تسرب البيانات الحساسة. يوصى بتحديث الأنظمة المتضررة وتفعيل إجراءات الأمان اللازمة. — يُنصح بتحديث البرامج ومراجعة الإعدادات الأمنية. 🔗 للمزيد: https://securityonline.info/ovn-heap-over-read-packet-leakage-advisory/

    Post summary

    The post announces two new heap‑over‑read vulnerabilities (CVE-2026-5265, CVE-2026-5367) and urges affected users to apply updates to mitigate data leakage risks.

    00030900
    268 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5367 A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an infl… https://www.cve.org/CVERecord?id=CVE-2026-5367

    Post summary

    The message reports the discovery of CVE-2026-5367 in OVN, noting that remote attackers can craft DHCPv6 SOLICIT packets to exploit the flaw, but provides no further technical details or remarks on PoC, exploitation, or patch status.

    00000100
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5367 [ADVISORY] CVE-2026-5367 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5367

    Post summary

    The provided text only references an advisory link for CVE-2026-5367, with no additional details about exploitation, patches, or technical specifics.

    0000027
    4.0K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-5367 Heap over-read in OVN DHCPv6 Client ID processing leaks memory via DHCPv6 and ICMP responses -- https://seclists.org/oss-sec/2026/q2/183

    Post summary

    The post announces CVE‑2026‑5367, detailing a heap over‑read in OVN DHCPv6 client ID handling that results in memory leaks via DHCPv6 and ICMP responses, with a link to a security mailing‑list discussion.

    00000111
    3.7K followersView on X

Explore more