CVE-2025-0650 describes a high-severity flaw in Open Virtual Network (OVN) that allows specially crafted UDP packets to bypass egress Access Control Lists (ACLs). This vulnerability specifically impacts OVN installations with a logical switch configured with DNS records and egress ACLs, potentially leading to unauthorized access to virtual machines and containers. With a CVSS score of 8.1 (HIGH), the attack requires no user interaction and has high impacts on confidentiality, integrity, and availability, though it has a high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Fast Datapath For Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Fast Datapath For Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.