CVE-2025-0650
HIGHDescription
A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Moderate risk: more likely to be exploited than 53% of all known CVEs.
References
- https://access.redhat.com/errata/RHSA-2025:1083
- https://access.redhat.com/errata/RHSA-2025:1084
- https://access.redhat.com/errata/RHSA-2025:1085
- https://access.redhat.com/errata/RHSA-2025:1086
- https://access.redhat.com/errata/RHSA-2025:1087
- https://access.redhat.com/errata/RHSA-2025:1088
- https://access.redhat.com/errata/RHSA-2025:1089
- https://access.redhat.com/errata/RHSA-2025:1090
- https://access.redhat.com/errata/RHSA-2025:1091
- https://access.redhat.com/errata/RHSA-2025:1092
- https://access.redhat.com/errata/RHSA-2025:1093
- https://access.redhat.com/errata/RHSA-2025:1094
- https://access.redhat.com/errata/RHSA-2025:1095
- https://access.redhat.com/errata/RHSA-2025:1096
- https://access.redhat.com/errata/RHSA-2025:1097
- https://access.redhat.com/security/cve/CVE-2025-0650
- https://bugzilla.redhat.com/show_bug.cgi?id=2339537
- https://www.openwall.com/lists/oss-security/2025/01/22/5
- http://www.openwall.com/lists/oss-security/2025/01/22/11
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-02-06.