CVE-2026-25804: Linuxfoundation Antrea

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.

Affected products

  • Linuxfoundation Antrea: before 2.3.2 (fixed in 2.3.2); from 2.4.0, before 2.4.3 (fixed in 2.4.3)

Published 2026-02-06. Last modified 2026-06-17.