HarborGuard / CVE
Back to search
HIGHCVE-2026-25804Published Modified CNA GitHub_M

CVE-2026-25804: Antrea has invalid enforcement order for network policy rules caused by integer overflow

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.

Metrics

CVSS v4.0
8.0
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • antrea-io / antrea
    < 2.3.2 · >= 2.4.0, < 2.4.3
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U