Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-11614

Опубликовано: 17 дек. 2024
Источник: redhat
CVSS3: 7.4

Описание

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

Отчет

Affected versions are only vulnerable if the Vhost-based application registers devices with the RTE_VHOST_USER_NET_COMPLIANT_OL_FLAGS flag. OVS-DPDK uses the DPDK Vhost library but does not pass this flag, so it is affected but not vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7dpdkNot affected
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.11Not affected
Fast Datapath for RHEL 7openvswitch2.12Not affected
Fast Datapath for RHEL 8openvswitch2.11Not affected
Fast Datapath for RHEL 8openvswitch2.12Not affected
Fast Datapath for RHEL 8openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.15Not affected
Fast Datapath for RHEL 8openvswitch2.16Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2327955dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
6 месяцев назад

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

CVSS3: 7.4
nvd
6 месяцев назад

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

CVSS3: 7.4
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
6 месяцев назад

An out-of-bounds read vulnerability was found in DPDK's Vhost library ...

suse-cvrf
5 месяцев назад

Security update for dpdk

7.4 High

CVSS3