Critical severity9.1NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2026-25804
CVE-2026-25804
Description
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
antrea.io/antreaGo | < 2.3.2 | 2.3.2 |
antrea.io/antreaGo | >= 2.4.0, < 2.4.3 | 2.4.3 |
Affected products
5- antrea-io/antreav5Range: < 2.3.2
- ghsa-coords3 versionspkg:golang/antrea.io/antreapkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 2.3.2+ 2 more
- (no CPE)range: < 2.3.2
- (no CPE)range: < 0.0.20260226T182644-150000.1.149.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
7- github.com/antrea-io/antrea/commit/86c4b6010f3be536866f339b632621c23d7186fanvdPatchWEB
- github.com/antrea-io/antrea/pull/7496nvdIssue TrackingPatchWEB
- github.com/antrea-io/antrea/security/advisories/GHSA-86x4-wp9f-wrr9nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-86x4-wp9f-wrr9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25804ghsaADVISORY
- gist.github.com/antoninbas/c429cc3e5bb8479ba7ff38fd6fde59d9ghsaWEB
- github.com/antrea-io/antrea/blob/main/docs/antrea-network-policy.mdghsaWEB
News mentions
0No linked articles in our index yet.