CVE-2026-5265: Red Hat Fast Datapath For Red Hat Enterprise Linux 10

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM.

Affected products

  • Red Hat Fast Datapath For Red Hat Enterprise Linux 10: before 0:25.03.2-100.el10fdp (fixed in 0:25.03.2-100.el10fdp); before 0:25.09.2-103.el10fdp (fixed in 0:25.09.2-103.el10fdp)
  • Red Hat Fast Datapath For Red Hat Enterprise Linux 8: before 0:21.12.0-145.el8fdp (fixed in 0:21.12.0-145.el8fdp); before 0:23.06.4-30.el8fdp (fixed in 0:23.06.4-30.el8fdp)
  • Red Hat Fast Datapath For Red Hat Enterprise Linux 9: before 0:23.06.4-30.el9fdp (fixed in 0:23.06.4-30.el9fdp); before 0:23.09.6-16.el9fdp (fixed in 0:23.09.6-16.el9fdp); before 0:24.03.7-82.el9fdp (fixed in 0:24.03.7-82.el9fdp); before 0:25.03.2-100.el9fdp (fixed in 0:25.03.2-100.el9fdp); before 0:25.09.2-103.el9fdp (fixed in 0:25.09.2-103.el9fdp)
  • Red Hat Fast Datapath For Rhel 7
  • Red Hat Fast Datapath For Rhel 8
  • Red Hat Fast Datapath For Rhel 9

Published 2026-04-24. Last modified 2026-06-17.