CVE-2026-5367: Red Hat Fast Datapath For Red Hat Enterprise Linux 10

High severity, CVSS 8.6. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

Affected products

  • Red Hat Fast Datapath For Red Hat Enterprise Linux 10: before 0:25.03.2-100.el10fdp (fixed in 0:25.03.2-100.el10fdp); before 0:25.09.2-103.el10fdp (fixed in 0:25.09.2-103.el10fdp)
  • Red Hat Fast Datapath For Red Hat Enterprise Linux 8: before 0:21.12.0-145.el8fdp (fixed in 0:21.12.0-145.el8fdp); before 0:23.06.4-30.el8fdp (fixed in 0:23.06.4-30.el8fdp)
  • Red Hat Fast Datapath For Red Hat Enterprise Linux 9: before 0:23.06.4-30.el9fdp (fixed in 0:23.06.4-30.el9fdp); before 0:23.09.6-16.el9fdp (fixed in 0:23.09.6-16.el9fdp); before 0:24.03.7-82.el9fdp (fixed in 0:24.03.7-82.el9fdp); before 0:25.03.2-100.el9fdp (fixed in 0:25.03.2-100.el9fdp); before 0:25.09.2-103.el9fdp (fixed in 0:25.09.2-103.el9fdp)
  • Red Hat Fast Datapath For Rhel 8
  • Red Hat Fast Datapath For Rhel 9
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-04-24. Last modified 2026-08-25.