Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rccg-5mcc-m2cf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtio_dev_rx_batch_packed().

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtio_dev_rx_batch_packed().

EPSS

Процентиль: 69%
0.00606
Низкий

7.7 High

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
redhat
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
nvd
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
debian
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicio ...

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость функции virtio_dev_rx_batch_packed набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.00606
Низкий

7.7 High

CVSS3

Дефекты

CWE-665