Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86564

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 3.3

Описание

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

Отчет

A malicious guest with access to the VDUSE virtio-net control virtqueue can trigger this flaw. Red Hat has rated this as having a security impact of Low.

Меры по смягчению последствий

No mitigation is currently available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 10openvswitch3.5Fix deferred
Fast Datapath for RHEL 10openvswitch3.6Fix deferred
Fast Datapath for RHEL 8openvswitch2.11Fix deferred
Fast Datapath for RHEL 8openvswitch2.12Fix deferred
Fast Datapath for RHEL 8openvswitch2.13Fix deferred
Fast Datapath for RHEL 8openvswitch2.15Fix deferred
Fast Datapath for RHEL 8openvswitch2.16Fix deferred
Fast Datapath for RHEL 8openvswitch2.17Fix deferred
Fast Datapath for RHEL 8openvswitch3.1Fix deferred
Fast Datapath for RHEL 9openvswitch2.17Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2529682dpdk: dpdk: Missing length validation before reading command_data in virtio-net control queue handler

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
6 дней назад

Missing length validation before reading command_data in virtio-net control queue handler

CVSS3: 3.3
nvd
7 дней назад

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

CVSS3: 3.3
debian
7 дней назад

A flaw was found in DPDK lib/vhost. Missing length validation before r ...

CVSS3: 3.3
github
7 дней назад

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

3.3 Low

CVSS3