CVE-2025-0650 | Ovn: egress acls may be bypassed via specially crafted udp packet

A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.

Published: 2025-01-23 Last update: 2026-04-15 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-0650 is rated Moderate Risk (43.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-0650

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-03 0.38% 0.13% -0.25%
2 2026-03-02 1.30% 0.38% -0.91%
3 2025-11-21 1.30%

Full EPSS history (20 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-0650

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.1 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 5.9 [email protected]

Weakness enumeration for CVE-2025-0650

OS Trackers for CVE-2025-0650

vendor priority summary link
debian not yet assigned CVE-2025-0650 not yet assigned priority: Debian including 1 source packages (ovn), 4 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 3, open 1. https://security-tracker.debian.org/tracker/CVE-2025-0650
redhat high https://access.redhat.com/security/cve/CVE-2025-0650
suse high CVE-2025-0650 severity important: SUSE including 144 source package names (latest:selinux-policy-20230523+git27.6fee49569-1.1, latest:selinux-policy-targeted-20230523+git27.6fee49569-1.1, …), 401 product×package rows across 35 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Image SLE-Micro, … (35 product lines)): Fixed 401. https://www.suse.com/security/cve/CVE-2025-0650/
ubuntu medium CVE-2025-0650 medium priority: Ubuntu including 1 source packages (ovn), 5 status rows across 5 suites (focal, jammy, noble, oracular, upstream): released 5. https://ubuntu.com/security/CVE-2025-0650

Affected software / configurations for CVE-2025-0650

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2025-0650

URL Tags
https://access.redhat.com/errata/RHSA-2025:1083
https://access.redhat.com/errata/RHSA-2025:1084
https://access.redhat.com/errata/RHSA-2025:1085
https://access.redhat.com/errata/RHSA-2025:1086
https://access.redhat.com/errata/RHSA-2025:1087
https://access.redhat.com/errata/RHSA-2025:1088
https://access.redhat.com/errata/RHSA-2025:1089
https://access.redhat.com/errata/RHSA-2025:1090
https://access.redhat.com/errata/RHSA-2025:1091
https://access.redhat.com/errata/RHSA-2025:1092
https://access.redhat.com/errata/RHSA-2025:1093
https://access.redhat.com/errata/RHSA-2025:1094
https://access.redhat.com/errata/RHSA-2025:1095
https://access.redhat.com/errata/RHSA-2025:1096
https://access.redhat.com/errata/RHSA-2025:1097
https://access.redhat.com/security/cve/CVE-2025-0650
https://bugzilla.redhat.com/show_bug.cgi?id=2339537
https://www.openwall.com/lists/oss-security/2025/01/22/5
http://www.openwall.com/lists/oss-security/2025/01/22/11
cvelogic Threat Intelligence