Red Hat Product Errata RHSA-2026:11700 - Security Advisory Issued: 2026-04-29 Updated: 2026-04-29 RHSA-2026:11700 - Security Advisory Overview Updated Packages Synopsis Important: ovn24.03 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for ovn24.03 is now available for Fast Datapath for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description OVN, the Open Virtual Network, is a system to support virtual network abstraction. OVN complements the existing capabilities of OVS to add native support for virtual network abstractions, such as virtual L2 and L3 overlays and security groups. Security Fix(es): ovn: ovn: Heap Over-Read in ICMP Error Response Generation - security issue (CVE-2026-5265) ovn: OVN: Information disclosure via crafted DHCPv6 packets (CVE-2026-5367) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Fast Datapath 9 x86_64 Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE) 9 ppc64le Red Hat Enterprise Linux Fast Datapath (for IBM z Systems) 9 s390x Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64) 9 aarch64 Fixes BZ - 2453458 - CVE-2026-5265 ovn: ovn: Heap Over-Read in ICMP Error Response Generation - security issue BZ - 2455863 - CVE-2026-5367 ovn: OVN: Information disclosure via crafted DHCPv6 packets FDP-3265 - CLONE [ovn24.03 fast-datapath-rhel-9] - Upstream: error log in ovn-northd.log when set port security for vrrp FDP-3490 - CLONE [ovn24.03 fast-datapath-rhel-9] - Upstream: Add dash version suffix to the internal version string FDP-3497 - CLONE [ovn24.03 fast-datapath-rhel-9] - Upstream: Add dash version suffix to the internal version string FDP-3695 - OVN 24.03 FDP-OVN-26.n4 RHEL 9 Release CVEs CVE-2026-5265 CVE-2026-5367 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Fast Datapath 9 SRPM ovn24.03-24.03.7-82.el9fdp.src.rpm SHA-256: 8a76761bbdbae769b1982857a92c90dca4dd3ce0231dd71482f448b899565e9d x86_64 ovn24.03-24.03.7-82.el9fdp.x86_64.rpm SHA-256: 11c13a8f09e00dd2523ddf244e2ed5c6adbe73d45f5334ceac46d336703caeeb ovn24.03-central-24.03.7-82.el9fdp.x86_64.rpm SHA-256: b4dd43e40265960335a388eead85ab7c9c3c764d4e0fc1a1e1e2c2806b3301d2 ovn24.03-central-debuginfo-24.03.7-82.el9fdp.x86_64.rpm SHA-256: 1ec201b3f7b55ab2d16813edb9c29ee1c5c5a2a2a233d2f3eb8b49d77cf95f41 ovn24.03-debuginfo-24.03.7-82.el9fdp.x86_64.rpm SHA-256: ee276f3a32868300983cfb0a748e4852203d87a89b2559d9f5d417498ac503cb ovn24.03-debugsource-24.03.7-82.el9fdp.x86_64.rpm SHA-256: 7046de87bffed83d67e159aeb8b494586f6659c1b0941f00919817f26f86852c ovn24.03-host-24.03.7-82.el9fdp.x86_64.rpm SHA-256: 208bd328d6127f6dfb1433e0e90b0cb5ab4e9e86d788cb51f5c0b123e9817948 ovn24.03-host-debuginfo-24.03.7-82.el9fdp.x86_64.rpm SHA-256: d3b8d9947835a279d76b310d93963215c6f4f300cee015acbd7b9287e3f84547 ovn24.03-vtep-24.03.7-82.el9fdp.x86_64.rpm SHA-256: f05bcc0aaf0a2ee685faa6711d8cd2d1f95031da0425925b6821f3de01de3309 ovn24.03-vtep-debuginfo-24.03.7-82.el9fdp.x86_64.rpm SHA-256: 94245a4cfdbbcbb82b87681a010da10fc536894de4e0f50e176228ac0b40d29f Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE) 9 SRPM ovn24.03-24.03.7-82.el9fdp.src.rpm SHA-256: 8a76761bbdbae769b1982857a92c90dca4dd3ce0231dd71482f448b899565e9d ppc64le ovn24.03-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: 4c3ed0cb050f9c122fd4ddcfe340517a1b823bf0e1b10fa7fd91f6c3d6967cd7 ovn24.03-central-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: c408a78b77a33c8d54975c335637e56d326b9b8487f4c5aa37689d8a95fc3bf2 ovn24.03-central-debuginfo-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: 2bfa6cae69690ff51e2fa2f2778fefdede303aac68fda027306fba0708bf084d ovn24.03-debuginfo-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: 9ad180df5335e5ecb8a52e92a13c20cd2a5a7ea04deeae4744c44c008cfb03fd ovn24.03-debugsource-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: 52e5ed17f2133346e1a73c9fe11724bb10e5fe4a96b484b63a4aa9c7322f1403 ovn24.03-host-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: f086585a3515a8f813e09db0a04d5b050ec1abcd052e21e9d73554069a3daf00 ovn24.03-host-debuginfo-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: a269742f4f7733915d092036f077528bf2b5763d9e32e40950c1b957de488d07 ovn24.03-vtep-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: 264016d117c59d0094d4e17a1441d5c738e70f66f13d25cced5bfb23bf924edd ovn24.03-vtep-debuginfo-24.03.7-82.el9fdp.ppc64le.rpm SHA-256: ad2dfe7e25883c427ba2a872891360923b9e83ef95ebf5f8f61323358571b3f9 Red Hat Enterprise Linux Fast Datapath (for IBM z Systems) 9 SRPM ovn24.03-24.03.7-82.el9fdp.src.rpm SHA-256: 8a76761bbdbae769b1982857a92c90dca4dd3ce0231dd71482f448b899565e9d s390x ovn24.03-24.03.7-82.el9fdp.s390x.rpm SHA-256: 2936c0ed751371ced4c1574b52ce3caccc54069f4e8df7e37899e2e2a5e94e86 ovn24.03-central-24.03.7-82.el9fdp.s390x.rpm SHA-256: c282b661272d2cc2754c7899f84d56824c6b5312ec229687e79da0aa74825dc3 ovn24.03-central-debuginfo-24.03.7-82.el9fdp.s390x.rpm SHA-256: 4552f2f71101e5ff778c37c9cb1080c385a02fd8e7427cfb4e08f5198fa3a720 ovn24.03-debuginfo-24.03.7-82.el9fdp.s390x.rpm SHA-256: d8f5900f012c42b3da86f011af559a8b8fef4d977c72e0347117f48a99f75c8c ovn24.03-debugsource-24.03.7-82.el9fdp.s390x.rpm SHA-256: 9f4e4d67bf5ceb5302d5ed3355a0c48af7e35a62f4e7a1a5c9a38dc3d083babf ovn24.03-host-24.03.7-82.el9fdp.s390x.rpm SHA-256: dad2a45117429c5252c43289b79ec771b17c2b37a643eba98111100867243f6e ovn24.03-host-debuginfo-24.03.7-82.el9fdp.s390x.rpm SHA-256: 4b45af09cc45afa36f10231181076e39b275b2c70113fe593f65c16dd28e9e1a ovn24.03-vtep-24.03.7-82.el9fdp.s390x.rpm SHA-256: bc809928fc5e03ecc160b49dffa406879a84c1975623c96f1e50e1d66b184663 ovn24.03-vtep-debuginfo-24.03.7-82.el9fdp.s390x.rpm SHA-256: 82e9c1e9080ff91584cc0e2cd0f52efd4d0796319f38e6c79299affab7e404fd Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64) 9 SRPM ovn24.03-24.03.7-82.el9fdp.src.rpm SHA-256: 8a76761bbdbae769b1982857a92c90dca4dd3ce0231dd71482f448b899565e9d aarch64 ovn24.03-24.03.7-82.el9fdp.aarch64.rpm SHA-256: bfa566994a5ae0826b36e1232e3a6eca2fcd68f04af244a9f6e03dade495b79b ovn24.03-central-24.03.7-82.el9fdp.aarch64.rpm SHA-256: c3a2265a54b8fe15d965f221c3ce2e3c08e63e2154253c4c8427e5ec203f8490 ovn24.03-central-debuginfo-24.03.7-82.el9fdp.aarch64.rpm SHA-256: 30edd49848f40d4a15b3c9665d5d1368329147195cd7b38c599a9b7b020cc451 ovn24.03-debuginfo-24.03.7-82.el9fdp.aarch64.rpm SHA-256: ac22be3d1378cf7ac6c025a247ace2cb92304c7c6b3a0b5272b92f324cb31b5c ovn24.03-debugsource-24.03.7-82.el9fdp.aarch64.rpm SHA-256: 4e8c15fb737d6e8e5be06c97d52a09f92fb68e6c183720d6faf497ba49b7460e ovn24.03-host-24.03.7-82.el9fdp.aarch64.rpm SHA-256: 9c53e1b67c0783fc6aa06955c080cd28b64352dc2ec72cc0c2ed7873b54cd2ff ovn24.03-host-debuginfo-24.03.7-82.el9fdp.aarch64.rpm SHA-256: 84cec2c1a648e42c899c3e3930d379b377fef003521301f2ceea7ba0f302cbf6 ovn24.03-vtep-24.03.7-82.el9fdp.aarch64.rpm SHA-256: 49f995ad7222c0babd9dca3284b0f84afda38874935a34179f1d5eaca7b0e3dc ovn24.03-vtep-debuginfo-24.03.7-82.el9fdp.aarch64.rpm SHA-256: d977f41988684142a39094cec0809a0e2f144536db598ad042811bd0ee396a3e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
Red Hat has issued an Important security update for OVN 24.03 in Fast Datapath for RHEL 9, addressing two vulnerabilities: a heap over-read during ICMP error response generation (CVE-2026-5265, CVSS 6.5 MEDIUM) and an information disclosure via crafted DHCPv6 packets (CVE-2026-5367, CVSS 8.6 HIGH). The fix is included in the updated package version ovn24.03-24.03.7-82.el9fdp, which should be applied following Red Hat's standard update procedures.