—
GO-2026-4461
Antrea has invalid enforcement order for network policy rules caused by integer overflow in antrea.io/antrea
Details
Antrea has invalid enforcement order for network policy rules caused by integer overflow in antrea.io/antrea.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: antrea.io/antrea before v2.3.2, from v2.4.0 before v2.4.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/antrea.io/antrea
Introduced in:
0No fixed version published yet for antrea.io/antrea (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/antrea-io/antrea/security/advisories/GHSA-86x4-wp9f-wrr9[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25804[ADVISORY]
- https://gist.github.com/antoninbas/c429cc3e5bb8479ba7ff38fd6fde59d9[WEB]
- https://github.com/antrea-io/antrea/blob/main/docs/antrea-network-policy.md[WEB]
- https://github.com/antrea-io/antrea/commit/86c4b6010f3be536866f339b632621c23d7186fa[WEB]
- https://github.com/antrea-io/antrea/pull/7496[WEB]