Описание
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory.
Отчет
Red Hat OpenStack Platform versions 7 to 9 provided openvswitch-dpdk as a technical preview for customers, it was provided without support and is not intended on being deployed in production. Red Hat Ceph Storage version 3 provides ceph bundled with DPDK as a technical preview for customers. It was provided without support and is not intended on being deployed in production.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Fast Datapath for RHEL 7 | dpdk | Will not fix | ||
| Red Hat Ceph Storage 3 | ceph | Not affected | ||
| Red Hat Enterprise Linux 8 | dpdk | Not affected | ||
| Red Hat Enterprise Linux 8 | openvswitch | Not affected | ||
| Red Hat Enterprise Linux 9 | dpdk | Affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | openvswitch-dpdk | Will not fix | ||
| Red Hat OpenShift Enterprise 3 | openvswitch | Will not fix | ||
| Red Hat OpenStack Platform 10 (Newton) | dpdk | Affected | ||
| Red Hat OpenStack Platform 11 (Ocata) | dpdk | Will not fix | ||
| Red Hat OpenStack Platform 11 (Ocata) | openvswitch | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
The DPDK vhost-user interface does not check to verify that all the re ...
EPSS
6.1 Medium
CVSS3