A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtio_dev_rx_batch_packed()
.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Data_plane_development_kit | Dpdk | * | 19.11 (including) |
Fast Datapath for Red Hat Enterprise Linux 8 | RedHat | openvswitch2.13-0:2.13.0-25.el8fdp.1 | * |
Red Hat Enterprise Linux 8 | RedHat | dpdk-0:19.11.3-1.el8 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | dpdk-0:19.11-5.el8_2 | * |
Dpdk | Ubuntu | devel | * |
Dpdk | Ubuntu | focal | * |
Dpdk | Ubuntu | trusty | * |
Dpdk | Ubuntu | upstream | * |