CVE-2026-25804 HIGH

CVE-2026-25804: Antrea has invalid enforcement order for network policy rules caused by integer overflow

Vendor Antrea-Io
Product antrea
Weakness CWE-287 · Improper authentication
Published February 6, 2026
Last update February 9, 2026

CVSS base score

8.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U

What the vulnerability does

01Description

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority values. This results in potentially incorrect traffic enforcement. This issue has been patched in versions 2.4.3.

Key dates

02Disclosure timeline

February 6, 2026 CVE published
February 9, 2026 Record updated