https://seclists.org/oss-sec/2026/q2/182: [ADVISORY] CVE-2026-5265: Heap Over-ad in ICMP Error sponse Generation
Published Apr 20, 2026
·Updated
Affected Software
1 affected component
Open vSwitch OVN<24.03.8, <24.09.4, <25.03.3, <25.09.3, <26.03.1
Frequently Asked Questions
1
What is the severity of CVE-2026-5265?
CVE-2026-5265 is classified as a medium severity vulnerability due to potential information leakage.
2
How do I fix CVE-2026-5265?
To fix CVE-2026-5265, upgrade to the latest secure version of Open vSwitch that mitigates this vulnerability.
3
What systems are affected by CVE-2026-5265?
CVE-2026-5265 affects multiple versions of Open Virtual Network (OVN) used within Open vSwitch.
4
What exploits exist for CVE-2026-5265?
Exploits for CVE-2026-5265 involve sending crafted ICMP error message packets that lead to heap over-read vulnerabilities.
5
What are the potential impacts of CVE-2026-5265?
The potential impact of CVE-2026-5265 includes leaking sensitive information from the memory heap of the affected system.