CVE-2026-45840

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/05/2026
Last modified:
27/05/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> openvswitch: cap upcall PID array size and pre-size vport replies<br /> <br /> The vport netlink reply helpers allocate a fixed-size skb with<br /> nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID<br /> array via ovs_vport_get_upcall_portids(). Since<br /> ovs_vport_set_upcall_portids() accepts any non-zero multiple of<br /> sizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID<br /> array large enough to overflow the reply buffer, causing nla_put() to<br /> fail with -EMSGSIZE and hitting BUG_ON(err

Impact