CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:antrea:*:*:*:*:*:kubernetes:*:*
cpe:2.3:a:linuxfoundation:antrea:*:*:*:*:*:kubernetes:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Antrea es una solución de red de Kubernetes diseñada para ser nativa de Kubernetes. Antes de las versiones 2.3.2 y 2.4.3, el sistema de asignación de prioridad de políticas de red de Antrea tiene un error de desbordamiento aritmético uint16 que causa cálculos incorrectos de prioridad de OpenFlow al manejar un gran número de políticas con varios valores de prioridad. Esto resulta en una aplicación de tráfico potencialmente incorrecta. Este problema ha sido parcheado en la versión 2.4.3.

28 Feb 2026, 00:30

Type Values Removed Values Added
First Time Linuxfoundation
Linuxfoundation antrea
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/antrea-io/antrea/commit/86c4b6010f3be536866f339b632621c23d7186fa - () https://github.com/antrea-io/antrea/commit/86c4b6010f3be536866f339b632621c23d7186fa - Patch
References () https://github.com/antrea-io/antrea/pull/7496 - () https://github.com/antrea-io/antrea/pull/7496 - Issue Tracking, Patch
References () https://github.com/antrea-io/antrea/security/advisories/GHSA-86x4-wp9f-wrr9 - () https://github.com/antrea-io/antrea/security/advisories/GHSA-86x4-wp9f-wrr9 - Patch, Vendor Advisory
CPE cpe:2.3:a:linuxfoundation:antrea:*:*:*:*:*:kubernetes:*:*

06 Feb 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 23:15

Updated : 2026-06-17 10:25


NVD link : CVE-2026-25804

Mitre link : CVE-2026-25804

CVE.ORG link : CVE-2026-25804


JSON object : View

Products Affected

linuxfoundation

  • antrea
CWE
CWE-287

Improper Authentication

CWE-770

Allocation of Resources Without Limits or Throttling