#1136284 trixie-pu: package ovn/25.03.0-1 (CVE-2026-5265 + CVE-2026-5367)

#1136284#5
Date:
2026-05-11 14:10:14 UTC
From:
To:
Hi,

[ Reason ]
I'd like to upload OVN to Trixie p-u to address CVE-2026-5265
and CVE-2026-5367.

[ Impact ]
- CVE-2026-5265: Heap Over-Read in ICMP Error Response Generation.
- CVE-2026-5367: Heap over-read in OVN DHCPv6 Client ID processing.

[ Tests ]
Both patches (for each CVE) contain unit tests.

[ Risks ]
Patches aren't so big, should be ok, especially with the included
tests.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
2 patches, plus refresh of 2, no other change.

Please allow me to uplaod ovn/25.03.0-1+deb13u1 to Trixie p-u.

Cheers,

Thomas Goirand (zigo)

#1136284#12
Date:
2026-05-24 09:12:00 UTC
From:
To:
Hi,

Please go ahead.

Thanks,

#1136284#19
Date:
2026-07-06 20:21:04 UTC
From:
To:
Hi Thomas,

Have you seen the ack from Jonathan? Unfortunately now it is too late
for the next point release but still would be great for the next one.

Regards,
Salvatore

#1136284#24
Date:
2026-07-07 12:34:32 UTC
From:
To:
Missed it. Just uploaded it.

Cheers,

Thomas Goirand (zigo)