REDHAT-BUG-2455863: High severity Open vSwitch ovn-controller vulnerability

Published Apr 7, 2026
·
Updated

Multiple versions of OVN (Open Virtual Network) are vulnerable to crafted DHCPv6 packets that could potentially read out-of-bounds, leaking adjacent info stored on the heap.

OVN supports configuring DHCPv6 options for Logical Switch Ports. When configured we allow handling of DHCPv6 requests in a userspace thread called pinctrl. The thread accesses user-controlled packet data and copies some of it in the process of creating a reply packet.

When building a DHCPv6 ADVERTISE reply, the handler echoes the Client ID option using the option's self-declared length without validating it against the actual packet bounds. A workload can send a crafted DHCPv6 SOLICIT with an inflated Client ID length field, causing ovn-controller to copy heap memory beyond the valid packet data into the reply. The reply is then delivered back to the attacker's VM port.

Affected Software

1 affected component
Open vSwitch ovn-controller

Event History

Apr 7, 2026
Data Sourced
via Red Hat·08:12 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2455863?

The severity of REDHAT-BUG-2455863 is high, rated at 7.

2

What vulnerabilities are addressed in REDHAT-BUG-2455863?

REDHAT-BUG-2455863 addresses vulnerabilities related to crafted DHCPv6 packets that could cause out-of-bounds reads.

3

How do I fix REDHAT-BUG-2455863?

To fix REDHAT-BUG-2455863, you should update to the latest version of the Open vSwitch ovn-controller.

4

Which versions of Open vSwitch are affected by REDHAT-BUG-2455863?

Multiple versions of OVN (Open Virtual Network) are affected by REDHAT-BUG-2455863.

5

What potential risk is associated with REDHAT-BUG-2455863?

The potential risk associated with REDHAT-BUG-2455863 is the leakage of adjacent information stored on the heap.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203