https://seclists.org/oss-sec/2026/q2/184: [ADVISORY] CVE-2026-5265: Heap Over-ad in ICMP Error sponse Generation
Published Apr 20, 2026
·Updated
Affected Software
1 affected component
Open vSwitch OVN<24.03.8, <24.09.4, <25.03.3, <25.09.3, <26.03.1
Frequently Asked Questions
1
What is the severity of CVE-2026-5265?
CVE-2026-5265 has a high severity due to the potential for information leakage and out-of-bounds read vulnerabilities.
2
How do I fix CVE-2026-5265?
To fix CVE-2026-5265, users should update their Open vSwitch OVN to the latest version where the vulnerability has been patched.
3
Which versions of Open vSwitch OVN are affected by CVE-2026-5265?
CVE-2026-5265 affects multiple versions of Open vSwitch OVN prior to the patch release.
4
What are the consequences of exploiting CVE-2026-5265?
Exploiting CVE-2026-5265 could lead to the disclosure of sensitive information stored in adjacent memory.
5
Is CVE-2026-5265 common in network environments?
CVE-2026-5265 is particularly concerning in environments that make extensive use of OVN for network virtualization.