Описание
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Отчет
A malicious guest with access to the VDUSE virtio-net control virtqueue can trigger this flaw. Red Hat has rated this as having a security impact of Low.
Меры по смягчению последствий
No mitigation is currently available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Fast Datapath for RHEL 10 | openvswitch3.5 | Fix deferred | ||
| Fast Datapath for RHEL 10 | openvswitch3.6 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.11 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.12 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.13 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.15 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.16 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.17 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch3.1 | Fix deferred | ||
| Fast Datapath for RHEL 9 | openvswitch2.17 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.3 Low
CVSS3
Связанные уязвимости
Missing length validation before reading command_data in virtio-net control queue handler
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
A flaw was found in DPDK lib/vhost. Missing length validation before r ...
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
3.3 Low
CVSS3