Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1059

Опубликовано: 23 апр. 2018
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory.

Отчет

Red Hat OpenStack Platform versions 7 to 9 provided openvswitch-dpdk as a technical preview for customers, it was provided without support and is not intended on being deployed in production. Red Hat Ceph Storage version 3 provides ceph bundled with DPDK as a technical preview for customers. It was provided without support and is not intended on being deployed in production.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7dpdkWill not fix
Red Hat Ceph Storage 3cephNot affected
Red Hat Enterprise Linux 8dpdkNot affected
Red Hat Enterprise Linux 8openvswitchNot affected
Red Hat Enterprise Linux 9dpdkAffected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openvswitch-dpdkWill not fix
Red Hat OpenShift Enterprise 3openvswitchWill not fix
Red Hat OpenStack Platform 10 (Newton)dpdkAffected
Red Hat OpenStack Platform 11 (Ocata)dpdkWill not fix
Red Hat OpenStack Platform 11 (Ocata)openvswitchWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1544298dpdk: Information exposure in unchecked guest physical to host virtual address translations

EPSS

Процентиль: 38%
0.0017
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 8 лет назад

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

CVSS3: 6.1
nvd
почти 8 лет назад

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

CVSS3: 6.1
debian
почти 8 лет назад

The DPDK vhost-user interface does not check to verify that all the re ...

suse-cvrf
около 7 лет назад

Security update for dpdk

suse-cvrf
больше 7 лет назад

Security update for dpdk-thunderxdpdk

EPSS

Процентиль: 38%
0.0017
Низкий

6.1 Medium

CVSS3