Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3839

Опубликовано: 29 апр. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate msg->payload.inflight.num_queues, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

Отчет

This flaw does not affect Red Hat Ceph Storage 3 and 4 as dpdk (embedded in ceph source rpm) is not built in the packages, therefore the vulnerable code is not available in the resulting RPM and the issue cannot be exploited.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchWill not fix
Fast Datapath for RHEL 7openvswitch2.11Not affected
Fast Datapath for RHEL 7openvswitch2.13Out of support scope
Fast Datapath for RHEL 7openvswitch2.15Out of support scope
Fast Datapath for RHEL 8openvswitch2.11Not affected
Fast Datapath for RHEL 8openvswitch2.17Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 7dpdkOut of support scope
Red Hat Enterprise Linux 8dpdkWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2025882DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash

EPSS

Процентиль: 30%
0.00108
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

CVSS3: 7.5
nvd
почти 3 года назад

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

CVSS3: 7.5
debian
почти 3 года назад

A flaw was found in the vhost library in DPDK. Function vhost_user_set ...

CVSS3: 7.5
github
почти 3 года назад

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость функции vhost_user_set_inflight_fd() набора библиотек и драйверов для быстрой обработки пакетов DPDK, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00108
Низкий

7.5 High

CVSS3