CVE-2026-25804
EUVD-2026-693606.02.2026, 23:15
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linuxfoundation | antrea | 𝑥 < 2.3.2 |
| linuxfoundation | antrea | 2.4.0 ≤ 𝑥 < 2.4.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration